← Back to context

Comment by gizmodo59

4 hours ago

When would I use this over the plugin in codex? Which I think can be invoked from cli as well

The plugin, including when invoked through the Codex CLI, is great for scanning the repo you're currently working in. The standalone Security CLI/SDK uses the same scanner, but is built for running security across many repos over time: org-wide scans, historical results, deduplication, false-positive tracking, budget controls, and CI integration.

We've been talking to hundreds of engineering and security teams, and their feedback is shaping what we build.

Like Promptfoo, our goal is practical tooling that fits into the workflows teams already have.