Allow only OpenAi key? Requires Cyber registration? Yes. Yes. Useless.
Just a few days back, I was reviewing some small bit of legacy DSA signature verification code, to get a sense of how safe it is to reuse - purely defensive, precautionary work and the context of it was there. But I simply wasn't able to use Codex Security: it threw refusal tantrums on every step of the way. Even the reasoning went like "nah, this is false positive, this is defensive code hardening, I'll nuke the subagent and tell it so" , followed by a refusal.
In the end, I was only able to do partial review with vanilla Codex w/o Codex Security.