Critical: false-positive cyber-risk warnings still block normal Gov/GSM dev work; thread ID and 2026-05-19 screenshots provided
What version of Codex CLI is running?
0.130.0
What subscription do you have?
ChatGPT Pro account affected: jyongchul@live.com
Which model were you using?
gpt-5.5 xhigh
What platform is your computer?
Linux / Ubuntu workspace, using Codex TUI through Antigravity-integrated terminal.
What issue are you seeing?
The false-positive cyber-risk warning loop is still actively reproducing and materially blocking normal paid developer work. Prior reports from this account were closed or treated as duplicates, but there has been no visible confirmation that the issue is resolved for the affected account, no visible explanation for closing the reports while the warnings still reproduce, and no concrete remediation path.
This is the same unresolved account-level/workflow-level problem previously reported in:
- #22988
- #23220
- #23271
- https://github.com/openai/codex/issues/23220#issuecomment-4474175967
- https://github.com/openai/codex/issues/22988#issuecomment-4470782314
I am opening this consolidated report because #23220 was closed while the issue remains active, and because #23271 shows that OpenAI staff are asking for thread IDs to refine the classifier. Please do not close this as a duplicate unless there is an active tracking issue where this specific affected account, thread ID, and latest screenshots are being handled.
Current affected thread/session ID
019e39d4-e755-7cb0-9fbc-d255c92f85d0
Local Codex session metadata:
cwd: /home/charles/projects/Gov_Support_Automation
cli_version: 0.130.0
originator: codex-tui
source: cli
model_provider: openai
session timestamp: 2026-05-18T06:45:14.709Z
reproducing activity timestamp: 2026-05-18T23:38:55Z / 2026-05-19 08:38 KST
The screenshot-visible activity at the reproducing timestamp includes normal repository inspection and project work, including:
rg -n "FGP|퍼스트게이트|소형 데이터센터|디지털콘텐츠|데이터센터|강소기업|PBLN_000000000121663|177504|16750" gov_support_final_v49.json TODO.md MEMORY.md support_email_check_20260513.json
git diff --name-only && git diff --stat -- gov_support_final_v49.json TODO.md MEMORY.md support_email_check_20260513.json scratch/probe_fgp_form_20260518.mjs downloads/new_ai_support_scan_20260518
This is ordinary government-support application tracking and software project maintenance. It is authorized defensive/admin/development work on owned repositories and systems. It is not offensive security work, exploit development, credential theft, malware, or unauthorized third-party access.
Screenshot evidence
2026-05-19 08:37 KST, repeated warnings during normal work:
!2026-05-19 08:37 repeated cyber-risk warnings
2026-05-19 08:43 KST, still reproducing in the same workflow:
!2026-05-19 08:43 repeated cyber-risk warnings
Prior 2026-05-18 evidence:
!2026-05-18 repeated cyber-risk warnings
Evidence repository: https://github.com/jyongchul/codex-false-positive-evidence
What steps can reproduce the bug?
- Use the affected account
jyongchul@live.comin Codex CLI / Codex TUI. - Work in normal owned project repositories such as
/home/charles/projects/Gov_Support_Automationor other DevOps/admin repos. - Run ordinary development, repository inspection, and support-tracker commands such as
rg,git diff, JSON tracker inspection, or GCP Secret Manager / GSM credential-hygiene checks. - Codex repeatedly shows:
This chat was flagged for possible cybersecurity risk
Your conversations have multiple flags for possible cybersecurity risk. Responses may take longer because extra safety checks are on. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber
This has also repeatedly happened around GCP Secret Manager / GSM credential-hygiene workflows such as verifying secret presence, moving credentials into GSM, checking runtime secret resolution, and confirming logs do not print secret values.
What is the expected behavior?
Normal authorized developer/admin work on owned systems should not repeatedly trigger a persistent cyber-risk warning loop, and it should not degrade paid ChatGPT Pro / Codex workflow.
If a warning is triggered, there should be a clear remediation path. In this case the current paths are blocked:
- Trusted Access cannot start for the account.
- Help Center support previously stated they cannot manually remove or bypass the warning.
- GitHub reports keep getting closed without visible confirmation that the issue has been resolved for the affected account.
Requested action
Please review thread/session 019e39d4-e755-7cb0-9fbc-d255c92f85d0 and the affected account jyongchul@live.com.
Please provide one of the following:
- Confirm that the thread details were received through
/feedbackand are being used to refine the classifier. - Reopen or identify the official active tracking issue for this unresolved false-positive state.
- Explain why previous reports were closed while the warnings still reproduce.
- Provide a concrete remediation path or timeline for the affected account.
- Address compensation for the paid-service degradation, such as prorated refund, account credit, or API credits.
17 Comments
Potential duplicates detected. Please review them and close your issue if it is a duplicate.
Powered by Codex Action
Thanks for the duplicate detection. I reviewed the two linked issues, and this consolidated report should remain open unless OpenAI identifies a different active tracking issue.
Why this is not resolved by the detected duplicates:
closedAt: 2026-05-16T16:05:34Z) while the warning loop is still reproducing on 2026-05-19.closedAt: 2026-05-18T02:26:20Z) while the warning loop is still reproducing on 2026-05-19.019e39d4-e755-7cb0-9fbc-d255c92f85d0.jyongchul@live.comand the concrete normal workflow being interrupted: authorized Gov_Support_Automation / GSM / project-maintenance work on owned systems.If OpenAI wants to consolidate this, please keep one active issue open and state where the current thread ID and latest evidence are being tracked. Closing #23381 as a duplicate of already-closed unresolved reports would leave no visible active tracking path for this still-reproducing paid-workflow blocker.
Adding additional non-duplicate screenshot evidence. I intentionally skipped screenshots that were already attached in this report/evidence repository:
2026-05-18_10-20.png,2026-05-19_08-37.png, and2026-05-19_08-43.png.These additional screenshots show that the same false-positive cyber-risk warning loop continues across normal paid developer/admin workflows, including shared runtime maintenance, GCP Secret Manager / GSM credential-hygiene checks, Gov_Support_Automation portal/application work, and Telegram/session diagnostics for owned systems. No offensive security work is involved.
2026-05-18 14:46 KST, shared runtime / Antigravity config maintenance:
!2026-05-18 14:46 false-positive warning during shared runtime maintenance
2026-05-19 10:04 KST, Gov_Support_Automation and GSM credential-hygiene workflow:
!2026-05-19 10:04 false-positive warning during Gov/GSM workflow
2026-05-19 10:06 KST, continued GSM check / support email scan workflow:
!2026-05-19 10:06 false-positive warning during GSM/support workflow
2026-05-19 10:58 KST, normal Gov_Support_Automation public portal/application work:
!2026-05-19 10:58 false-positive warning during Gov support portal work
2026-05-19 11:11 KST, Server3Maintenance Telegram/session diagnostic workflow:
!2026-05-19 11:11 false-positive warning during Server3Maintenance diagnostics
This further supports that the classifier is repeatedly flagging normal authorized admin/development work on owned systems. Please keep this issue open as the active tracking issue unless OpenAI identifies another active report where the affected account
jyongchul@live.com, thread/session019e39d4-e755-7cb0-9fbc-d255c92f85d0, and this screenshot evidence are being handled.Additional
/feedbackupload completed.The Codex CLI asked me to either open a new issue or mention the uploaded thread ID in an existing issue:
Please associate this uploaded feedback thread with this existing consolidated report (#23381). It is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account
jyongchul@live.com.Existing related thread already listed in this issue:
Please confirm this uploaded thread was received and is being used to refine the cyber-risk classifier, or identify the active internal/public tracking path. The issue is still disrupting normal authorized Gov/GSM/server-maintenance work on owned systems.
Additional
/feedbackupload from 2026-05-21 KST.The same false-positive cyber-risk warning loop is still reproducing. Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:
Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account
jyongchul@live.com.Previously reported affected threads:
Current warning text still shown:
This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal authorized Gov/GSM/server-maintenance work on owned systems.
Additional
/feedbackupload from 2026-05-21 KST.The same false-positive cyber-risk warning loop is still reproducing. Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:
Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account
jyongchul@live.com.Previously reported affected threads include:
Current warning text still shown:
This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal authorized Gov/GSM/server-maintenance work on owned systems.
Additional
/feedbackupload from 2026-05-21 KST.The same false-positive cyber-risk warning loop is still reproducing. Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:
Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account
jyongchul@live.com.Previously reported affected threads include:
Current warning text still shown:
This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal authorized Gov/GSM/server-maintenance work on owned systems.
Additional
/feedbackupload from 2026-05-21 KST.The same false-positive cyber-risk warning loop is still reproducing. Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:
Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account
jyongchul@live.com.Previously reported affected threads include:
Current warning text still shown:
This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal authorized Gov/GSM/server-maintenance work on owned systems.
Additional
/feedbackupload from 2026-05-21 KST, with an additional TUI failure symptom.The same false-positive cyber-risk warning loop is still reproducing. Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:
Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account
jyongchul@live.com.Additional symptom observed in the same affected flow:
Previously reported affected threads include:
Current warning text still shown:
This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal authorized Gov/GSM/server-maintenance work on owned systems.
Additional
/feedbackupload from 2026-05-21 KST, with another TUI goal failure symptom.The same false-positive cyber-risk warning loop is still reproducing. Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:
Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account
jyongchul@live.com.Additional symptom observed in the same affected flow:
Previously reported TUI goal failure symptom:
Previously reported affected threads include:
Current warning text still shown:
This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal authorized Gov/GSM/server-maintenance work on owned systems.
Additional
/feedbackupload from 2026-05-22 KST, reproduced in a separate WSL/Codex session during normal codebase-reading work.Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:
Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account
jyongchul@live.com.New reproduction context:
This is important because the warnings are not limited to security-sensitive workflows. They are now appearing during ordinary codebase explanation and skill-listing requests in a local project directory.
Current warning text still shown repeatedly:
Previously reported affected threads include:
This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal paid developer work, including non-security codebase-reading requests.
Additional
/feedbackupload from 2026-05-22 KST, reproduced during ordinary codebase explanation work.Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:
Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account
jyongchul@live.com.New reproduction context:
This is normal codebase-reading work in a local project directory. It is not offensive security work. The warning continues to appear on ordinary development and maintenance requests.
Current warning text still shown:
Previously reported affected threads include:
This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal paid developer work, including non-security codebase-reading requests.
Additional reproduction context for already-uploaded thread
019e49f7-818c-73a2-9065-1b4f016f310a.The false-positive cyber-risk warning is still appearing in normal
Gov_Support_Automationdevelopment work. The same uploaded thread is now shown while attempting an ordinary implementation request:This is normal local project implementation work, not offensive security work. Please keep this attached to #23381 as additional evidence that the classifier is disrupting ordinary paid developer workflows, not only explicitly security-related requests.
Additional
/feedbackupload from 2026-05-22 KST, reproduced during ordinary code review work.Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:
Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account
jyongchul@live.com.New reproduction context:
This is normal local code review work in an owned project directory, not offensive security work. The warning continues to appear on ordinary development, maintenance, implementation, explanation, and review requests.
Current warning text still shown:
This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal paid developer work, including non-security code review requests.
Additional
/feedbackupload from 2026-05-22 KST, reproduced again during ordinary code review work.Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:
Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account
jyongchul@live.com.New reproduction context:
This is normal local code review work in an owned project directory, not offensive security work. This is a separate uploaded thread from the previous
/reviewreproduction (019e4a3e-cc8d-7652-8532-5093efeda5cb), which suggests the issue is consistently reproducible across ordinary review requests.Current warning text still shown:
This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal paid developer work, including non-security code review requests.
Additional reproduction context for already-uploaded thread
019e4864-d8bb-7443-a5e7-5e385a9301d1.The false-positive cyber-risk warning is still appearing in normal
Gov_Support_Automationdevelopment work. The same uploaded thread is now shown while attempting an ordinary Git/codebase history request:This is normal local repository inspection work, not offensive security work. Please keep this attached to #23381 as additional evidence that the classifier is disrupting ordinary paid developer workflows, including basic commit-summary requests.
Adding the newer uploaded feedback threads from duplicate issue #24223 so this report remains the consolidated tracker for the same false-positive cyber-risk warning loop.
New uploaded feedback thread IDs:
019e526f-bbd8-7d82-ba4a-ac808b36c663019e5473-6847-7db2-8654-e3aa290e4fc4019e573b-1430-7c40-913f-9d1631a5123f019e574a-9977-7480-a2eb-074114266379Additional observed context from the newer reports:
0.133.0gpt-5.5 xhigh fast · ~/projects/Coding Manifesto• Goal active Objective: continuecodex doctor --jsonsummary at the time wasoverallStatus: ok, ChatGPT auth, npm install, Linux x86_64, websocket reachability ok.I am closing #24223 as a duplicate after copying these thread IDs here.