Defensive Cybersecurity Agent: The Codex Security Pattern for Claude
OpenAI's GPT-5.5-Cyber (85.6% CyberGym) and their Codex Security plugin model a complete vulnerability-to-patch workflow: deep codebase scan → attack path analysis → auto-generated patch → SARIF/CodeQL export.
- ▸TypeScript source — types.ts, scanner.ts, attack-path.ts, patcher.ts, sarif-export.ts, index.ts
- ▸10-section practitioner guide — intro through operations checklist
- ▸GitHub Actions YAML — drop-in CI integration with incremental caching
- ▸SARIF/CodeQL export — feeds directly into GitHub Code Scanning
- ▸Workflow diagram — Mermaid visual of the full four-stage pipeline
- ▸Honest operations guide — cost tuning, rate limit handling, known limitations
## goes-well-with
From the same shelf
Agentic AI Security Policy Template Pack
Downloadable Markdown + YAML policy templates giving IT teams the acceptable-use, blast-radius, approval-gate, and logging scaffolding to safely deploy agentic AI coding tools like Claude Code, Codex, and Grok Build.
Agentic Migration Playbook: API Endpoint Modernization
For DevOps and platform engineers with a real migration deadline — the complete Claude Code workflow you'd otherwise spend months reverse-engineering.
Ansible Automation Starter Kit for Linux Sysadmins
12 production Ansible playbooks for Linux sysadmins — annotated, tested, ready to run.
## not-ready-to-buy
Take the field notes instead
One practical write-up a week from the same workbench these kits come from — plus reader pricing when new kits ship.