OpenAI’s Codex Security scanned 1.2 million commits during its private beta and surfaced over 10,000 high-severity findings. Those numbers got the attention of every security-conscious engineering team, including ours. The more interesting question isn’t whether an AI agent can identify vulnerabilities in source code. It clearly can. The question we keep coming back to at StackHawk is whether finding those issues in source code is enough to secure a running system. Our view is that it isn’t.