Comment by gregwebs
3 hours ago
Just ran it on a small repo. It ran for almost an hour and then got interrupted. It drained half my weekly usage on a Pro plan.
npx codex-security scan .
[00:00] Preparing scan
[00:00] Authentication: stored Codex credentials.
[00:03] Preparing scan
[01:20] Running scan
[01:20] Preflight: worker delegation supported (up to 8 worker slots).
[52:47] Running scan
codex-security: Could not save the Codex Security scan: Repository HEAD changed while the scan was running. Start a new scan.
codex-security: Partial output was kept at ...
Working as intended
Classic.
So it drained $5?
Can’t speak to the results, but the cost isn’t high.
I plan to hack it to use openrouter and Kimi K3 or GLM 5.2 to keep expenses reasonable.
For context can you share the line count?
No need to hack it, we'll add proper support for this.
Give this a try https://infosec.exchange/@st3fan/117000352530023032
FYI: Kimi K3 is relatively expensive on open router API pricing for agentic tasks, or at least that's been my experience playing around with it.
They just opened the weights. I expect competition from various providers will drop the price a bit. But you're right. I'd hope a model closer to GLM 5.2's price would be sufficiently useful.
1 reply →
Pro is 10$ a month. You get what you pay for lol.
No, Pro is $100 or $200/mo. Even Plus is $20/mo. Where's this $10/mo Pro plan?
Oof, that's a bad outcome. Half your weekly usage and a 50-minute scan just to get a HEAD error at the end is not acceptable. --max-cost can help limit estimated spend, but that doesn't fix the underlying problem or give you your quota back. We need to handle a changing checkout and partial results much better. Sorry you ran into this. Please send me an email.
Damn. Just ran it and it used 5 years worth of Pro usage in 5 minutes.
If ya wouldn't mind crediting me a quick 60 months that would be great.