CodeMarine Dev · Codex

Independent security around Codex.

Independent scanning for Codex changes today, with stronger command and MCP mediation in active development.

Codex coverage
INTEGRATION PROFILE Beta
Provider
Codex CLI, IDE and desktop surfaces
Primary transport
Workspace watcher, plugin and write adapter
Workspace scanning
Available
Blanket runtime protection
Not claimed

What the integration can see and where it stops.

Workspace observation and pre-execution control are shown separately.

OBSERVE

Evidence CodeMarine can inspect

  • Workspace changes regardless of the Codex surface
  • Apply-patch write activity through the available adapter
  • Dependencies and agent configuration written to the project
PREVENTIVE PATH

Defined blocking potential

  • Supported write operations when blocking setup is enabled
LIMITS

What you should not assume

  • The default integration is readiness-focused today
  • Codex Bash and MCP interception are planned
  • Hosted or specialized tool paths may sit outside local hook coverage

Native controls protect Codex. CodeMarine protects the shared environment.

Keep provider permissions and sandboxes. Add one deterministic policy around the workspace and the rest of your stack.

NATIVE LAYERProvider permissions and containment

Controls the surfaces and execution modes owned by the provider.

CODEMARINE LAYERCross-provider workspace policy

Secures resulting code, software supply chain and supported actions under one control model.

Install the CodeMarine skills for Codex.

Install the CodeMarine app first, then add the shared CodeMarine security skills to Codex.

codemarine agents install codex --skills

The app supplies the scanner. The provider skill or adapter connects it to Codex.

  1. 01

    InstallPlace the supported adapter and configuration.

  2. 02

    VerifyCheck version, integrity and workspace binding.

  3. 03

    ProveRun a harmless nonce-bound canary through the real host.

  4. 04

    MaintainExpire proof when the host, policy or configuration changes.

Evaluate CodeMarine with Codex.

Map the current workspace, provider paths and limits before deciding which controls to rely on.

Sarge, the CodeMarine guardian