Upstream-first
Track OpenAI Codex Security improvements through a repeatable merge workflow—not a drifting rewrite.
Open source · Apache 2.0
Find, validate, and fix code vulnerabilities with Codex, Claude Code, GLM, Kimi, or Muse—while Bex preserves the evidence and scan contract.
One click on GitHub · No signup

Why Bex Security
Bex Security keeps orchestration, permissions, validation, and final artifacts stable while the agent layer evolves.
Track OpenAI Codex Security improvements through a repeatable merge workflow—not a drifting rewrite.
Use ACP as a clean runtime boundary for Codex, Claude Code, and future compatible agents.
Carry findings from discovery through validation, remediation, comparison, and publication.
Portable by design
Bex owns the security contract end to end. Compatible agents execute inside that boundary and drafts become results only after validation.
Your repository
Scoped source access, treated as inert data.
Bex workflow
Orchestration, permissions, schemas, and policy.
Agent runtime
Codex or Claude today; more as they prove compatibility.
Validated artifacts
Evidence is checked and sealed before publication.
Choose your agent
Use the setup that matches your coding agent while Bex Security keeps scope, validation, and artifacts consistent.
Try it locally
Install the published npm package, sign in to the default Codex agent, and start a report-only security scan.
Requires Node.js 22.13+ in the 22.x line, Node.js 24 or 26, and Python 3.10+. Scan only repositories you own or are authorized to assess.
npm install --global @bex-co/bex-security
bex-security login
bex-security scan /path/to/repositoryBex Security is an Apache-2.0, upstream-first fork of OpenAI Codex Security that runs evidence-driven repository scans with multiple coding agents and models.
Codex is the default. Alpha ACP integrations support Claude Code, native Kimi Code, and Muse Code; Claude Code can also route scans to GLM or Kimi models.
Ordinary scans are report-only. Repository files change only when you explicitly request patching, and draft pull requests require an additional create-PR option.
Project status
The stable core is available now. The open agent layer is alpha. The roadmap is public and contributions are welcome.
Install @bex-co/bex-security from npm and use the Bex or compatible Codex command.
The first vertical slices work and are being hardened with full-scan fixtures.
Kimi uses its native ACP server; Muse runs through Bex's bundled community ACP adapter.
New agents join when they pass the same capability and artifact contracts.
Vote for an open agent layer
A GitHub star tells us—and future contributors—that agent choice in code security is worth building for.
Open source · Upstream-first · Built in public