Repository navigation
Deep Security Scan fails terminally when its discovery triggers cyber safety #276
Copy link
Copy link
Open
Labels
area:artifactsSaved scan state, storage, sealing, recovery, history, and artifact integrity.Saved scan state, storage, sealing, recovery, history, and artifact integrity.area:authLogin, credentials, account access, and authentication recovery.Login, credentials, account access, and authentication recovery.area:deep-scanDeep Scan coordination, worker scheduling, coverage, convergence, and resume.Deep Scan coordination, worker scheduling, coverage, convergence, and resume.bugSomething isn't workingSomething isn't workingpriority:p1High-impact scan failure, integrity gap, or user-blocking regressionHigh-impact scan failure, integrity gap, or user-blocking regression
Description
Activity
- addedarea:authLogin, credentials, account access, and authentication recovery.Login, credentials, account access, and authentication recovery.area:costToken usage, cost estimates, spending limits, and quota visibility.Token usage, cost estimates, spending limits, and quota visibility.area:reportsHuman-readable reports, source excerpts, exports, and SARIF projections.Human-readable reports, source excerpts, exports, and SARIF projections.bugSomething isn't workingSomething isn't workingpriority:p1High-impact scan failure, integrity gap, or user-blocking regressionHigh-impact scan failure, integrity gap, or user-blocking regression
on Aug 15, 2026 mldangelo-oai commented
on Aug 15, 2026 CollaboratorMore actionsThanks for the detailed report. #267 adds replacement for refused Deep Scan workers, and #434 can preserve completed partial results. Neither change guarantees an access check before work starts or recovery when the coordinator itself is refused. Keeping this open for that remaining behavior; #56 tracks the related Standard-scan case.
- addedarea:artifactsSaved scan state, storage, sealing, recovery, history, and artifact integrity.Saved scan state, storage, sealing, recovery, history, and artifact integrity.area:deep-scanDeep Scan coordination, worker scheduling, coverage, convergence, and resume.Deep Scan coordination, worker scheduling, coverage, convergence, and resume.and removedarea:costToken usage, cost estimates, spending limits, and quota visibility.Token usage, cost estimates, spending limits, and quota visibility.area:reportsHuman-readable reports, source excerpts, exports, and SARIF projections.Human-readable reports, source excerpts, exports, and SARIF projections.
on Oct 8, 2026
Metadata
Metadata
Assignees
Labels
area:artifactsSaved scan state, storage, sealing, recovery, history, and artifact integrity.Saved scan state, storage, sealing, recovery, history, and artifact integrity.area:authLogin, credentials, account access, and authentication recovery.Login, credentials, account access, and authentication recovery.area:deep-scanDeep Scan coordination, worker scheduling, coverage, convergence, and resume.Deep Scan coordination, worker scheduling, coverage, convergence, and resume.bugSomething isn't workingSomething isn't workingpriority:p1High-impact scan failure, integrity gap, or user-blocking regressionHigh-impact scan failure, integrity gap, or user-blocking regression
Component
0.1.15(the local installation has since updated to0.1.16)deep-scan-mcp/v1; coordinator manifest schema:126.727.513510.146.026.5.2gpt-5.6-sol, reasoning effortxhighSummary
A Deep Security Scan launched from the Codex desktop app against an authorized local repository passed the plugin's capability preflight and spent an extended period in repeated discovery. The first-party discovery coordinator then terminated the entire durable scan because its own security-analysis content triggered the cyber-safety classifier.
This appears to be a coordination/preflight bug between the Codex Security plugin and the cyber-safety entitlement/classification layer. Even if Trusted Access for Cyber is required for this scan, that requirement should be detected before discovery starts. A worker-level classifier refusal should also be recoverable or recorded as incomplete coverage instead of causing a terminal failure after substantial work.
Steps to reproduce
Actual result
The scan changes to terminal
failedstatus duringdiscovery. The coordinator returns no successful discoverymanifestPath, no canonical report is generated, and the failed logical scan cannot be resumed in place.Exact error:
Expected result
One of the following should happen:
Privacy
No repository name/path, source code, scan ID, continuation token, or local artifact path is included here. I can submit the affected Codex session and sanitized diagnostics privately through in-product feedback if maintainers need correlation data.