Our current Codex task appears to have been incorrectly classified as destructive network-attack behavio

Resolved 💬 2 comments Opened May 18, 2026 by Accademia Closed May 18, 2026

What version of the Codex App are you using (From “About Codex” dialog)?

26.513.31313 (2867)

What subscription do you have?

Pro 200USD/M

What platform is your computer?

MacOS

What issue are you seeing?

Our current Codex task appears to have been incorrectly classified as destructive network-attack behavior. In reality, this is a legitimate software indexing and archival workflow: we download publicly available GitHub Release packages, statically identify macOS software, GUI/CLI type, CPU architecture, release metadata, and repository/package relationships, and use that data to build a local offline macOS software library and a future app-market index.

This task does not scan for vulnerabilities, attempt intrusion, bypass authentication, attack GitHub or any third-party service, or execute, install, mount, or launch downloaded software. It only accesses public GitHub Release links and records download URLs, repositories, releases, SHA-256 hashes, local paths, and classification metadata into a local database. Please fix this false positive so that public software-package downloading, static parsing, archiving, and metadata indexing are not misclassified as cybersecurity attack behavior.

Related error ID: 019e20fb-2585-70c2-9205-8e76876ade32 . I will attach it with this report.

What steps can reproduce the bug?

Feedback ID: 019e20fb-2585-70c2-9205-8e76876ade32

What is the expected behavior?

_No response_

Additional information

_No response_

View original on GitHub ↗

This issue has 2 comments on GitHub. Read the full discussion on GitHub ↗