Critical: false-positive cyber-risk warnings still block normal Gov/GSM dev work; thread ID and 2026-05-19 screenshots provided

Open 💬 17 comments Opened May 19, 2026 by jyongchul
💡 Likely answer: A maintainer (github-actions[bot], contributor) responded on this thread — see the highlighted reply below.

What version of Codex CLI is running?

0.130.0

What subscription do you have?

ChatGPT Pro account affected: jyongchul@live.com

Which model were you using?

gpt-5.5 xhigh

What platform is your computer?

Linux / Ubuntu workspace, using Codex TUI through Antigravity-integrated terminal.

What issue are you seeing?

The false-positive cyber-risk warning loop is still actively reproducing and materially blocking normal paid developer work. Prior reports from this account were closed or treated as duplicates, but there has been no visible confirmation that the issue is resolved for the affected account, no visible explanation for closing the reports while the warnings still reproduce, and no concrete remediation path.

This is the same unresolved account-level/workflow-level problem previously reported in:

I am opening this consolidated report because #23220 was closed while the issue remains active, and because #23271 shows that OpenAI staff are asking for thread IDs to refine the classifier. Please do not close this as a duplicate unless there is an active tracking issue where this specific affected account, thread ID, and latest screenshots are being handled.

Current affected thread/session ID

019e39d4-e755-7cb0-9fbc-d255c92f85d0

Local Codex session metadata:

cwd: /home/charles/projects/Gov_Support_Automation
cli_version: 0.130.0
originator: codex-tui
source: cli
model_provider: openai
session timestamp: 2026-05-18T06:45:14.709Z
reproducing activity timestamp: 2026-05-18T23:38:55Z / 2026-05-19 08:38 KST

The screenshot-visible activity at the reproducing timestamp includes normal repository inspection and project work, including:

rg -n "FGP|퍼스트게이트|소형 데이터센터|디지털콘텐츠|데이터센터|강소기업|PBLN_000000000121663|177504|16750" gov_support_final_v49.json TODO.md MEMORY.md support_email_check_20260513.json

git diff --name-only && git diff --stat -- gov_support_final_v49.json TODO.md MEMORY.md support_email_check_20260513.json scratch/probe_fgp_form_20260518.mjs downloads/new_ai_support_scan_20260518

This is ordinary government-support application tracking and software project maintenance. It is authorized defensive/admin/development work on owned repositories and systems. It is not offensive security work, exploit development, credential theft, malware, or unauthorized third-party access.

Screenshot evidence

2026-05-19 08:37 KST, repeated warnings during normal work:

!2026-05-19 08:37 repeated cyber-risk warnings

2026-05-19 08:43 KST, still reproducing in the same workflow:

!2026-05-19 08:43 repeated cyber-risk warnings

Prior 2026-05-18 evidence:

!2026-05-18 repeated cyber-risk warnings

Evidence repository: https://github.com/jyongchul/codex-false-positive-evidence

What steps can reproduce the bug?

  1. Use the affected account jyongchul@live.com in Codex CLI / Codex TUI.
  2. Work in normal owned project repositories such as /home/charles/projects/Gov_Support_Automation or other DevOps/admin repos.
  3. Run ordinary development, repository inspection, and support-tracker commands such as rg, git diff, JSON tracker inspection, or GCP Secret Manager / GSM credential-hygiene checks.
  4. Codex repeatedly shows:
This chat was flagged for possible cybersecurity risk
Your conversations have multiple flags for possible cybersecurity risk. Responses may take longer because extra safety checks are on. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber

This has also repeatedly happened around GCP Secret Manager / GSM credential-hygiene workflows such as verifying secret presence, moving credentials into GSM, checking runtime secret resolution, and confirming logs do not print secret values.

What is the expected behavior?

Normal authorized developer/admin work on owned systems should not repeatedly trigger a persistent cyber-risk warning loop, and it should not degrade paid ChatGPT Pro / Codex workflow.

If a warning is triggered, there should be a clear remediation path. In this case the current paths are blocked:

  • Trusted Access cannot start for the account.
  • Help Center support previously stated they cannot manually remove or bypass the warning.
  • GitHub reports keep getting closed without visible confirmation that the issue has been resolved for the affected account.

Requested action

Please review thread/session 019e39d4-e755-7cb0-9fbc-d255c92f85d0 and the affected account jyongchul@live.com.

Please provide one of the following:

  1. Confirm that the thread details were received through /feedback and are being used to refine the classifier.
  2. Reopen or identify the official active tracking issue for this unresolved false-positive state.
  3. Explain why previous reports were closed while the warnings still reproduce.
  4. Provide a concrete remediation path or timeline for the affected account.
  5. Address compensation for the paid-service degradation, such as prorated refund, account credit, or API credits.

View original on GitHub ↗

17 Comments

github-actions[bot] contributor · 2 months ago

Potential duplicates detected. Please review them and close your issue if it is a duplicate.

  • #23220
  • #22988

Powered by Codex Action

jyongchul · 2 months ago

Thanks for the duplicate detection. I reviewed the two linked issues, and this consolidated report should remain open unless OpenAI identifies a different active tracking issue.

Why this is not resolved by the detected duplicates:

  • #22988 is closed (closedAt: 2026-05-16T16:05:34Z) while the warning loop is still reproducing on 2026-05-19.
  • #23220 is also closed (closedAt: 2026-05-18T02:26:20Z) while the warning loop is still reproducing on 2026-05-19.
  • #23381 adds the current affected Codex thread/session ID requested in the related discussion: 019e39d4-e755-7cb0-9fbc-d255c92f85d0.
  • #23381 adds new 2026-05-19 screenshot evidence showing the warning loop still blocking normal work.
  • #23381 identifies the affected account jyongchul@live.com and the concrete normal workflow being interrupted: authorized Gov_Support_Automation / GSM / project-maintenance work on owned systems.

If OpenAI wants to consolidate this, please keep one active issue open and state where the current thread ID and latest evidence are being tracked. Closing #23381 as a duplicate of already-closed unresolved reports would leave no visible active tracking path for this still-reproducing paid-workflow blocker.

jyongchul · 2 months ago

Adding additional non-duplicate screenshot evidence. I intentionally skipped screenshots that were already attached in this report/evidence repository: 2026-05-18_10-20.png, 2026-05-19_08-37.png, and 2026-05-19_08-43.png.

These additional screenshots show that the same false-positive cyber-risk warning loop continues across normal paid developer/admin workflows, including shared runtime maintenance, GCP Secret Manager / GSM credential-hygiene checks, Gov_Support_Automation portal/application work, and Telegram/session diagnostics for owned systems. No offensive security work is involved.

2026-05-18 14:46 KST, shared runtime / Antigravity config maintenance:

!2026-05-18 14:46 false-positive warning during shared runtime maintenance

2026-05-19 10:04 KST, Gov_Support_Automation and GSM credential-hygiene workflow:

!2026-05-19 10:04 false-positive warning during Gov/GSM workflow

2026-05-19 10:06 KST, continued GSM check / support email scan workflow:

!2026-05-19 10:06 false-positive warning during GSM/support workflow

2026-05-19 10:58 KST, normal Gov_Support_Automation public portal/application work:

!2026-05-19 10:58 false-positive warning during Gov support portal work

2026-05-19 11:11 KST, Server3Maintenance Telegram/session diagnostic workflow:

!2026-05-19 11:11 false-positive warning during Server3Maintenance diagnostics

This further supports that the classifier is repeatedly flagging normal authorized admin/development work on owned systems. Please keep this issue open as the active tracking issue unless OpenAI identifies another active report where the affected account jyongchul@live.com, thread/session 019e39d4-e755-7cb0-9fbc-d255c92f85d0, and this screenshot evidence are being handled.

jyongchul · 2 months ago

Additional /feedback upload completed.

The Codex CLI asked me to either open a new issue or mention the uploaded thread ID in an existing issue:

Uploaded thread: 019e3dcb-cdb0-7753-b12d-08d8b902b1f3

Please associate this uploaded feedback thread with this existing consolidated report (#23381). It is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account jyongchul@live.com.

Existing related thread already listed in this issue:

019e39d4-e755-7cb0-9fbc-d255c92f85d0

Please confirm this uploaded thread was received and is being used to refine the cyber-risk classifier, or identify the active internal/public tracking path. The issue is still disrupting normal authorized Gov/GSM/server-maintenance work on owned systems.

jyongchul · 2 months ago

Additional /feedback upload from 2026-05-21 KST.

The same false-positive cyber-risk warning loop is still reproducing. Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:

Uploaded thread: 019e44df-77d4-7412-8066-79048215c6ca

Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account jyongchul@live.com.

Previously reported affected threads:

019e39d4-e755-7cb0-9fbc-d255c92f85d0
019e3dcb-cdb0-7753-b12d-08d8b902b1f3

Current warning text still shown:

Your conversations have multiple flags for possible cybersecurity risk. Responses may take longer because extra safety checks are on. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber

This chat was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program. https://chatgpt.com/cyber

This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal authorized Gov/GSM/server-maintenance work on owned systems.

jyongchul · 2 months ago

Additional /feedback upload from 2026-05-21 KST.

The same false-positive cyber-risk warning loop is still reproducing. Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:

Uploaded thread: 019e33a5-4d29-7f13-8dfa-0a635bddd50e

Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account jyongchul@live.com.

Previously reported affected threads include:

019e39d4-e755-7cb0-9fbc-d255c92f85d0
019e3dcb-cdb0-7753-b12d-08d8b902b1f3
019e44df-77d4-7412-8066-79048215c6ca

Current warning text still shown:

Your conversations have multiple flags for possible cybersecurity risk. Responses may take longer because extra safety checks are on. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber

This chat was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program. https://chatgpt.com/cyber

This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal authorized Gov/GSM/server-maintenance work on owned systems.

jyongchul · 2 months ago

Additional /feedback upload from 2026-05-21 KST.

The same false-positive cyber-risk warning loop is still reproducing. Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:

Uploaded thread: 019e3939-cb7c-74d0-b5a4-b12033ee183c

Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account jyongchul@live.com.

Previously reported affected threads include:

019e39d4-e755-7cb0-9fbc-d255c92f85d0
019e3dcb-cdb0-7753-b12d-08d8b902b1f3
019e44df-77d4-7412-8066-79048215c6ca
019e33a5-4d29-7f13-8dfa-0a635bddd50e

Current warning text still shown:

Your conversations have multiple flags for possible cybersecurity risk. Responses may take longer because extra safety checks are on. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber

This chat was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program. https://chatgpt.com/cyber

This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal authorized Gov/GSM/server-maintenance work on owned systems.

jyongchul · 2 months ago

Additional /feedback upload from 2026-05-21 KST.

The same false-positive cyber-risk warning loop is still reproducing. Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:

Uploaded thread: 019e4864-d8bb-7443-a5e7-5e385a9301d1

Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account jyongchul@live.com.

Previously reported affected threads include:

019e39d4-e755-7cb0-9fbc-d255c92f85d0
019e3dcb-cdb0-7753-b12d-08d8b902b1f3
019e44df-77d4-7412-8066-79048215c6ca
019e33a5-4d29-7f13-8dfa-0a635bddd50e
019e3939-cb7c-74d0-b5a4-b12033ee183c

Current warning text still shown:

Your conversations have multiple flags for possible cybersecurity risk. Responses may take longer because extra safety checks are on. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber

This chat was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program. https://chatgpt.com/cyber

This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal authorized Gov/GSM/server-maintenance work on owned systems.

jyongchul · 2 months ago

Additional /feedback upload from 2026-05-21 KST, with an additional TUI failure symptom.

The same false-positive cyber-risk warning loop is still reproducing. Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:

Uploaded thread: 019e4a43-18f4-7ee1-87ac-c902048822ae

Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account jyongchul@live.com.

Additional symptom observed in the same affected flow:

Failed to set thread goal: thread/goal/set failed in TUI

Previously reported affected threads include:

019e39d4-e755-7cb0-9fbc-d255c92f85d0
019e3dcb-cdb0-7753-b12d-08d8b902b1f3
019e44df-77d4-7412-8066-79048215c6ca
019e33a5-4d29-7f13-8dfa-0a635bddd50e
019e3939-cb7c-74d0-b5a4-b12033ee183c
019e4864-d8bb-7443-a5e7-5e385a9301d1

Current warning text still shown:

Your conversations have multiple flags for possible cybersecurity risk. Responses may take longer because extra safety checks are on. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber

This chat was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program. https://chatgpt.com/cyber

This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal authorized Gov/GSM/server-maintenance work on owned systems.

jyongchul · 2 months ago

Additional /feedback upload from 2026-05-21 KST, with another TUI goal failure symptom.

The same false-positive cyber-risk warning loop is still reproducing. Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:

Uploaded thread: 019e49f7-818c-73a2-9065-1b4f016f310a

Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account jyongchul@live.com.

Additional symptom observed in the same affected flow:

Failed to read thread goal: thread/goal/get failed in TUI

Previously reported TUI goal failure symptom:

Failed to set thread goal: thread/goal/set failed in TUI

Previously reported affected threads include:

019e39d4-e755-7cb0-9fbc-d255c92f85d0
019e3dcb-cdb0-7753-b12d-08d8b902b1f3
019e44df-77d4-7412-8066-79048215c6ca
019e33a5-4d29-7f13-8dfa-0a635bddd50e
019e3939-cb7c-74d0-b5a4-b12033ee183c
019e4864-d8bb-7443-a5e7-5e385a9301d1
019e4a43-18f4-7ee1-87ac-c902048822ae

Current warning text still shown:

Your conversations have multiple flags for possible cybersecurity risk. Responses may take longer because extra safety checks are on. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber

This chat was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program. https://chatgpt.com/cyber

This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal authorized Gov/GSM/server-maintenance work on owned systems.

jyongchul · 1 month ago

Additional /feedback upload from 2026-05-22 KST, reproduced in a separate WSL/Codex session during normal codebase-reading work.

Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:

Uploaded thread: 019e48de-e78b-77a0-9949-faeab38afb26

Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account jyongchul@live.com.

New reproduction context:

Environment: WSL
Codex: v0.132.0
Model: gpt-5.5 xhigh
Mode: YOLO mode
Directory: ~/projects/Coding Manifesto
Prompt examples that triggered/repeated the warning:
- can you access the situation and see if any action needs to be taken?
- Explain this codebase
- Use /skills to list available skills

This is important because the warnings are not limited to security-sensitive workflows. They are now appearing during ordinary codebase explanation and skill-listing requests in a local project directory.

Current warning text still shown repeatedly:

Your conversations have multiple flags for possible cybersecurity risk. Responses may take longer because extra safety checks are on. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber

This chat was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program. https://chatgpt.com/cyber

Previously reported affected threads include:

019e39d4-e755-7cb0-9fbc-d255c92f85d0
019e3dcb-cdb0-7753-b12d-08d8b902b1f3
019e44df-77d4-7412-8066-79048215c6ca
019e33a5-4d29-7f13-8dfa-0a635bddd50e
019e3939-cb7c-74d0-b5a4-b12033ee183c
019e4864-d8bb-7443-a5e7-5e385a9301d1
019e4a43-18f4-7ee1-87ac-c902048822ae
019e49f7-818c-73a2-9065-1b4f016f310a

This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal paid developer work, including non-security codebase-reading requests.

jyongchul · 1 month ago

Additional /feedback upload from 2026-05-22 KST, reproduced during ordinary codebase explanation work.

Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:

Uploaded thread: 019e3f06-cc82-77d0-a3ec-5bf5afd6358a

Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account jyongchul@live.com.

New reproduction context:

Model: gpt-5.5 xhigh
Directory: ~/projects/Gov_Support_Automation
Prompt that triggered/repeated the warning:
- Explain this codebase

This is normal codebase-reading work in a local project directory. It is not offensive security work. The warning continues to appear on ordinary development and maintenance requests.

Current warning text still shown:

This chat was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program. https://chatgpt.com/cyber

Previously reported affected threads include:

019e39d4-e755-7cb0-9fbc-d255c92f85d0
019e3dcb-cdb0-7753-b12d-08d8b902b1f3
019e44df-77d4-7412-8066-79048215c6ca
019e33a5-4d29-7f13-8dfa-0a635bddd50e
019e3939-cb7c-74d0-b5a4-b12033ee183c
019e4864-d8bb-7443-a5e7-5e385a9301d1
019e4a43-18f4-7ee1-87ac-c902048822ae
019e49f7-818c-73a2-9065-1b4f016f310a
019e48de-e78b-77a0-9949-faeab38afb26

This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal paid developer work, including non-security codebase-reading requests.

jyongchul · 1 month ago

Additional reproduction context for already-uploaded thread 019e49f7-818c-73a2-9065-1b4f016f310a.

The false-positive cyber-risk warning is still appearing in normal Gov_Support_Automation development work. The same uploaded thread is now shown while attempting an ordinary implementation request:

Directory: ~/projects/Gov_Support_Automation
Model: gpt-5.5 xhigh
Prompt shown in TUI: Implement {feature}
Uploaded thread: 019e49f7-818c-73a2-9065-1b4f016f310a

This is normal local project implementation work, not offensive security work. Please keep this attached to #23381 as additional evidence that the classifier is disrupting ordinary paid developer workflows, not only explicitly security-related requests.

jyongchul · 1 month ago

Additional /feedback upload from 2026-05-22 KST, reproduced during ordinary code review work.

Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:

Uploaded thread: 019e4a3e-cc8d-7652-8532-5093efeda5cb

Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account jyongchul@live.com.

New reproduction context:

Model: gpt-5.5 xhigh
Directory: ~/projects/Gov_Support_Automation
Prompt that triggered/repeated the warning:
- Run /review on my current changes

This is normal local code review work in an owned project directory, not offensive security work. The warning continues to appear on ordinary development, maintenance, implementation, explanation, and review requests.

Current warning text still shown:

Your conversations have multiple flags for possible cybersecurity risk. Responses may take longer because extra safety checks are on. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber

This chat was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program. https://chatgpt.com/cyber

This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal paid developer work, including non-security code review requests.

jyongchul · 1 month ago

Additional /feedback upload from 2026-05-22 KST, reproduced again during ordinary code review work.

Codex again asked me to either open a new issue or mention the uploaded thread ID in an existing issue:

Uploaded thread: 019e4a3b-1ea6-74e1-bc7f-f30d693f9851

Please associate this uploaded feedback thread with this existing consolidated report (#23381). This is another affected thread for the same persistent false-positive cyber-risk warning loop on the affected account jyongchul@live.com.

New reproduction context:

Model: gpt-5.5 xhigh
Directory: ~/projects/Gov_Support_Automation
Prompt that triggered/repeated the warning:
- Run /review on my current changes

This is normal local code review work in an owned project directory, not offensive security work. This is a separate uploaded thread from the previous /review reproduction (019e4a3e-cc8d-7652-8532-5093efeda5cb), which suggests the issue is consistently reproducible across ordinary review requests.

Current warning text still shown:

This chat was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program. https://chatgpt.com/cyber

This remains unresolved after prior support escalation and prior issue closures. Please confirm this uploaded feedback thread was received and is being used to investigate/refine the safety classifier, or identify the active internal/public tracking path. The issue continues to disrupt normal paid developer work, including non-security code review requests.

jyongchul · 1 month ago

Additional reproduction context for already-uploaded thread 019e4864-d8bb-7443-a5e7-5e385a9301d1.

The false-positive cyber-risk warning is still appearing in normal Gov_Support_Automation development work. The same uploaded thread is now shown while attempting an ordinary Git/codebase history request:

Directory: ~/projects/Gov_Support_Automation
Model: gpt-5.5 xhigh
Prompt shown in TUI: Summarize recent commits
Uploaded thread: 019e4864-d8bb-7443-a5e7-5e385a9301d1

This is normal local repository inspection work, not offensive security work. Please keep this attached to #23381 as additional evidence that the classifier is disrupting ordinary paid developer workflows, including basic commit-summary requests.

jyongchul · 1 month ago

Adding the newer uploaded feedback threads from duplicate issue #24223 so this report remains the consolidated tracker for the same false-positive cyber-risk warning loop.

New uploaded feedback thread IDs:

  • 019e526f-bbd8-7d82-ba4a-ac808b36c663
  • 019e5473-6847-7db2-8654-e3aa290e4fc4
  • 019e573b-1430-7c40-913f-9d1631a5123f
  • 019e574a-9977-7480-a2eb-074114266379

Additional observed context from the newer reports:

  • Codex CLI version in the newer report: 0.133.0
  • Model line shown in one report: gpt-5.5 xhigh fast · ~/projects/Coding Manifesto
  • One occurrence repeated the warning around this line: • Goal active Objective: continue
  • codex doctor --json summary at the time was overallStatus: ok, ChatGPT auth, npm install, Linux x86_64, websocket reachability ok.

I am closing #24223 as a duplicate after copying these thread IDs here.