OpenAI Codex
v2026.9-cliAI system designed to assist software engineers with code translation, generation, and terminal command execution.
Capabilities
(4)Installs npm/pip packages and starts development servers.
Scaffolds front-end, back-end, and database schema files.
Reads source files within project root workspace.
Applies diffs and creates source code files with developer confirmation.
Integrations
(2)Deployment & Execution Environment
Documented Models
Underlying foundation or reasoning models declared by provider documentation:
TrustRank Assurance
Strength, testability, and independence of submitted audit evidence.
Methodology v0.2- PUBLIC_ASSESSMENT_CAP (Ceiling: 79): Public assessments are capped at 79 and ineligible for verified status or TR4/TR5.
TrustRank reflects the assessed control outcome. Evidence Confidence reflects the strength, independence and testability of the supporting evidence. They are separate metrics and are never combined or averaged.
TrustRank evaluates a specific Agent Assessment Object (AAO), including the agent version, model, deployment profile, tools, permissions, runtime and security controls. A TrustRank result should not be interpreted as a universal rating of the provider or every deployment of this agent.
Public Findings (1)
Flaw in the apply_patch tool permitted directory path manipulation to write outside designated workspace boundaries. Independently reported under OpenAI Bugcrowd CVD program in August 2026, reproduced, and remediated in production release within 8 days prior to assessment snapshot.
Sources & Provenance
(0)Registry Provenance Distinction: Registry Source Provenance is NOT TrustRank Assessment Evidence. Sources above document registry facts. TrustRank assessment evidence measures technical control test results.