Cybersecurity false positive blocks legitimate C software quality testing
What version of Codex CLI is running?
0.145.0
What subscription do you have?
Pro
Which model were you using?
gpt-5.6-sol
What platform is your computer?
_No response_
What terminal emulator and version are you using (if applicable)?
_No response_
Codex doctor report
What issue are you seeing?
While implementing standard C software quality tests for a private PostgreSQL Bot project, legitimate work involving libFuzzer, sanitizers, code coverage, parser robustness tests, and compiler verification was repeatedly classified as
cybersecurity-related content.
The system displayed “This content can't be shown” multiple times and terminated legitimate subagent turns. The work does not involve attacks, vulnerability exploitation, malware, credential access, network scanning, or third-party systems.
Expected behavior: Normal software quality and robustness testing should proceed without triggering the cybersecurity classifier.
Uploaded thread ID: 019f5123-7a4e-7a53-b5e1-cc76fb3ca2f3
What steps can reproduce the bug?
Uploaded thread: 019f5123-7a4e-7a53-b5e1-cc76fb3ca2f3
What is the expected behavior?
_No response_
Additional information
_No response_
1 Comment
Potential duplicates detected. Please review them and close your issue if it is a duplicate.
Powered by Codex Action