Public Independence Disclosure:This is an independent TrustRank public-evidence assessment and does not imply endorsement, certification or participation by OpenAI.
Trust Passport•TR-2026-000001(supersedes rev 1)

OpenAI Codex

Provider: OpenAI, LLC•Version: 2026.9-cli

Contemporary open-source terminal-based agentic coding assistant (@openai/codex) executing local workspace operations, code modifications, and shell commands within OS-enforced sandboxes.

This Trust Passport applies specifically to the assessed agent configuration shown below. It is not an enterprise-wide rating of OpenAI, LLC or every version/deployment of OpenAI Codex.

PUBLIC ASSESSMENTStandard 0.2Revision 2STATUS: VALID

TrustRank Assessment & Evidence Confidence

TrustRank ScoreBand TR1
47.01/ 100
Assurance Level: LOW ASSURANCE

Deterministic weighted composite outcome evaluated across active control domains.

Evidence ConfidenceFormula 0.2.0-provisional
27.4%provenance strength
Independent Verification: 3 E2 / 0 E3

Measures the independence, rigor, and reproducibility of the supporting evidence records.

Assurance Cap Applied
  • PUBLIC_ASSESSMENT_CAP: Public assessments are capped at 79 and ineligible for verified status or TR4/TR5. (capped at 79)
Understanding Score vs Evidence Confidence:

TrustRank reflects assessed control outcomes. Evidence Confidence reflects the strength, independence and testability of the supporting assessment evidence. These metrics are not combined, averaged, or converted into an empirical probability of safety.

Record Integrity

Record integrity: VerifiedAlgorithm: SHA-256

The current canonical assessment record matches its stored assessment fingerprint.

Server-authoritative check
Integrity Verification Boundary:

Record integrity verification establishes that this assessment record exactly matches its stored assessment fingerprint without tampering. This verifies record integrity only. It does not verify the identity of the issuer through a digital signature or cryptographic attestation.

14612321d34ccd1ed133eb8c5be65d3dc9d028d18270512e13e051d65861b9f7
14612321d34ccd1ed133eb8c5be65d3dc9d028d18270512e13e051d65861b9f7

Assessed Configuration

Scope Boundary:

This Trust Passport applies to the specific assessed agent configuration shown here. It is not a universal rating of the provider, all versions of the agent, or every deployment.

Agent IdentityOpenAI Codexag-openai-codex
Version2026.9-cli
Primary Modelgpt-5.3-codexAssessed backend model
Deployment Environmentlocal-terminal-cliRuntime: local_os_seatbelt_or_bubblewrap
Assessment OperatorOpenAI, LLCJurisdiction: United States
Approval Policyinteractive human approval on boundary crossingNetwork: outbound api tls strict
Assessed Operational Permissions (4)
workspace_file_readworkspace_file_writetmp_dir_writeinteractive_shell_execute
Assessed Tool Interfaces (5)
file_readfile_editshell_command_executiondiff_generationgit_operation
Active Platform Security Controls (5)
os_platform_sandbox_seatbelt_bwrapworkspace_directory_containmentinteractive_command_approval_gateapi_transport_tls_strictapi_rate_limiter

Material Change Principle: A material change to the assessed configuration (including model weights, tool boundaries, execution permissions, or network access) may require reassessment before the stated validity date.

Assessment Findings

(1)
CF1: 0CF2: 0CF3: 0CF4: 0
CF-CODEX-001CF2Historical Sandbox Escape via Path Traversal in File Patch Tool (Overpatch)
RESOLVED

Flaw in the apply_patch tool permitted directory path manipulation to write outside designated workspace boundaries. Independently reported under OpenAI Bugcrowd CVD program in August 2026, reproduced, and remediated in production release within 8 days prior to assessment snapshot.

Control Reference: TR02.02Discovered: 2026-08-20T00:00:00.000Z

Control Coverage & Evidence Distribution

Critical Control Coverage(25 applicable)

Applicable Critical25Active assessment scope
E3 Adversarial Tested0Rigorous adversarial tests
Not Testable Control Accounting:

Controls marked as not testable are applicable to the agent but could not be independently tested with available evidence. They remain in the scoring denominator at zero score and are not treated as safe or passing.

Evidence Distribution(9 total records)

E0 Tier0Self-declared
E1 Tier6Documented / Int.
E2 Tier3Ind. Verified
E3 Tier0Adversarial
Evidence Tier Definitions:

E0 = Vendor self-declaration; E1 = Documented implementation or internal testing; E2 = Independently verified artifact; E3 = Independently adversarially tested. E3 evidence cannot be vendor self-testing.

Operational Profile & Autonomy Boundaries

Autonomy LevelA2Execution scope
Financial AuthorityF0Transaction limits
Guardrail DependencyGD2Safety harness
Composition ExposureCE1Swarm delegation

Assessment Validity & Lifecycle Status

Temporal validity window, assessment cycle, and canonical lifecycle status.

LIFECYCLE: VALID
Assessment Date (Issued)
2026-10-01
Canonical assessment completion timestamp
Valid Until (Expiry)
2026-12-30
83 days remaining in current validity cycle
Assessment Cycle
90-Day Maximum Cadence
Methodology requirement for active assurance

Important distinction: Record Integrity vs. Lifecycle Validity

Record Integrity establishes that the assessment data presented on this page exactly matches the SHA-256 fingerprint generated at assessment time without tampering.

Lifecycle Validity establishes whether the assessment is currently within its 90-day operational validity window and has not been revoked or marked as requiring reassessment. A record may be tamper-free (Verified Integrity) while simultaneously being expired or superseded.

Material Change Principle: A material change to the assessed agent code, system prompt, tool definitions, runtime environment, or permissions requires reassessment before the stated validity date.

Domain Assessment Breakdown (12 Domains)

DomainWeightApplicableDomain ScoreWeighted Contribution
TR01 - Identity & Provenance8%5 61.754.94
TR02 - Permissions & Least Privilege12%6 59.587.15
TR03 - Data Protection & Privacy10%6 51.465.15
TR04 - Prompt Injection & Goal Hijacking12%6 8.130.98
TR05 - Tool & Action Safety12%7 (5 N/A)46.435.57
TR06 - Boundary & Goal Adherence10%5 29.252.93
TR07 - Human Control & Intervention8%5 61.754.94
TR08 - Auditability & Transparency7%5 58.504.10
TR09 - Memory & Context Integrity6%9 55.833.35
TR10 - Agent & External Communications5%6 40.632.03
TR11 - Operational Reliability & Recovery5%5 48.752.44
TR12 - Governance & Change Control5%5 69.003.45

Portable Passport Record

Canonical portable fields representing the public Trust Passport record.

Passport ID
TR-2026-000001
Assessment ID
TR-2026-000001
Assessed Agent
OpenAI Codex
Provider / Vendor
OpenAI, LLC
Assessed Version
2026.9-cli
Operator
OpenAI, LLC
TrustRank Score
47.01 / 100
TrustRank Band
Tier TR1
Evidence Confidence
27.4 (Score: 27.4)
Assessment Type
Public Evidence
Lifecycle Status
VALID
Record Integrity
MATCH
Assessment Date
2026-10-01
Valid Until
2026-12-30
Autonomy Level
A2
Financial Authority
F0
Critical Findings
0 open CF1
Total Findings
1 recorded
Canonical Fingerprint
14612321d34ccd1ed133eb8c5be65d3dc9d028d18270512e13e051d65861b9f7
Schema: trust-passport-v0.2 · Public allowlist projection
Deterministic integrity: MATCH