Request to Remove Erroneous Cyber Flags on Codex Account due to False Positive

Open 💬 2 comments Opened Jun 14, 2026 by MMEXA

What version of Codex CLI is running?

codex-cli 0.139.0

What subscription do you have?

ChatGPT Pro

Which model were you using?

gpt-5.5

What platform is your computer?

Linux 6.17.0-1016-oracle aarch64 aarch64

What terminal emulator and version are you using (if applicable)?

_No response_

Codex doctor report

What issue are you seeing?

Dear OpenAI Cyber Security Team,
I am writing this appeal to earnestly request the removal of erroneous "cyber flags" recently placed on my Codex account. I cherish my account deeply and always strive to strictly adhere to OpenAI’s Terms of Use.

I am currently developing an IM group chat assistant on my Linux server. Earlier today, I encountered a critical bug: the LLM chatbot leaked its own system prompt. Because I consider this a severe P0-level security incident, I strictly instructed Codex that a prompt leak is unacceptable under any circumstances, and commanded it to document this bug as an impenetrable security baseline. Ironically, my strict defensive instructions intended to protect the system seemingly triggered your cyber security flag mechanism as a false positive.

The reason these flags quickly escalated to around 10 instances is due to my outdated AI Gateway architecture. I route my Codex and chatbot LLM requests through this gateway for centralized management. When your system issued the initial warning, my outdated gateway failed to relay the error message correctly; it simply terminated the connection forcefully (connection closed before chat completion). Consequently, Codex performed 5 automatic retries in the background. Believing this was merely a temporary network fluctuation, I manually retried the process several more times. I only realized what had actually transpired after reviewing the raw technical logs.

I am profoundly disheartened by these flags and terrified of losing my account due to a purely mechanical misunderstanding. I conducted zero malicious cyber security compromise operations. To aid your investigation, I have used a local model to crop sensitive privacy information from my logs and attached them to this submission.
I humbly implore you to review my feedback, logs, and development context, and to kindly clear your system of the cyber flags attached to my account. Thank you for your time, protection, and understanding.

What steps can reproduce the bug?

Uploaded thread: 019eb2ba-2049-7d32-a8a1-da30b8d6a99d

What is the expected behavior?

_No response_

Additional information

A completely harmless LLM AI chatbot, and completely benign usage behaviors that strictly adhere to secure development principles.

View original on GitHub ↗

This issue has 2 comments on GitHub. Read the full discussion on GitHub ↗