Every scan becomes comparable evidence.
A local-first workbench for OpenAI Codex Security: run, inspect, compare and govern AI-assisted security scans without losing the evidence, cost and operational context behind each result. Every run preserves model, effort, duration, tokens, estimated cost and severity in a local workspace — with versioned guardrails and optional publication as a GitHub Check.
- StackReact 19 · Vite · Tailwind · Hono · Node 24
- Scanner@openai/codex-securityindependente da OpenAI
- PersistenceSQLite local + estado do scanner
- Comparison1 baseline + até 5 candidatos
One terminal, one report, one bill — and no comparison
Security scans are usually reviewed in isolation: one terminal, one report, one bill. Which model reported more coverage? Which effort was worth the cost? Which run failed, and what survived it? Those answers vanish as soon as the terminal window closes.
Okami Sentinel turns those executions into a comparable system. Every run becomes an evidence channel with model, reasoning effort, duration, token volume, estimated cost, severity mix, findings and execution state preserved in one local workspace — nothing leaves the machine unless you explicitly publish a GitHub Check.
It is built for developers, DevSecOps engineers, security reviewers and AI engineers evaluating @openai/codex-security across real repositories. It is an independent workbench built around the scanner — not an official OpenAI product.
What Okami Sentinel does
Compare up to six runs
One baseline plus up to five candidates, with severity diff, unit economics ($ per finding, $ per High+), throughput and explicit decision objectives — instead of comparing reports from memory.
Evidence-first inspection
Filter findings by severity and lifecycle, inspect summaries and code locations, and trace the attack path with the evidence supporting each result.
Live telemetry with a cost ceiling
Status, phase, SSE events, duration, tokens and estimated cost while the scan runs. The cost envelope maps to the scanner's --max-cost guardrail and stops a run once the estimate crosses the configured ceiling.
Versioned guardrails with GitHub Checks
Local preflight policies, time-bounded explicit exceptions, a decision graph and optional publication as a GitHub Check — the same versioned policy annotates and gates pull requests through a reusable workflow.
Honest partial results
Failed scans that preserved findings remain comparable, with explicit FAILED and PARTIAL labels. An operational failure never becomes a passing security decision — and never a silent bootstrap.
Print-ready reports
An individual report from scan detail and a comparison report from a completed diff — branded, A4-aware and exportable as PDF straight from the browser, for handoff to whoever decides.
Spec sheet and when to use it
- Stack
- React 19 · Vite · Tailwind · Hono · Node 24
- Scanner
- @openai/codex-security (independente da OpenAI)
- Persistence
- SQLite local + estado do scanner
- Comparison
- 1 baseline + até 5 candidatos
- Authentication
- Assinatura Codex/ChatGPT · OPENAI_API_KEY (CI)
- Integration
- GitHub Actions · Checks (gate @v1)
- UI languages
- PT-BR · EN · ES · DE · FR
- Version
- 0.1.0 · em desenvolvimento ativo
Evaluating Codex Security on real repositories
Run the same repository with different models, efforts and scopes and answer with evidence which configuration reports more coverage, more High+ or better cost per finding — before standardizing the scan across the team.
Security gate on pull requests
Evaluate the local changeset against a versioned policy (.csb/guardrails.json) and publish the outcome as a required Check in branch protection — pass, warning, blocked or error, with no false success.
Handing results to decision makers
Hand off a single scan or a six-run comparison as a print-ready PDF — with executive summary, severity profile, findings and evidence — instead of pasting terminal output into a ticket.
Okami Sentinel FAQ
Is Okami Sentinel an official OpenAI product?
No. It is an independent local workbench built around OpenAI Codex Security — the scanner is OpenAI's, Sentinel is not. It runs, indexes and compares the scans, but does not modify or replace the scanner.
Do more findings mean a better scan?
No. Sentinel compares reported evidence, not ground-truth accuracy. More findings do not automatically make a better scan, and a missing finding does not prove remediation. Confirm findings and triage false positives before using precision, recall or F1.
Do I need an OpenAI API key?
Only to run autonomously in GitHub Actions. For local interactive use, an active Codex/ChatGPT session is enough. For CI and unattended gates, configure OPENAI_API_KEY as a repository secret — the application never reads or stores the secret's value, it only diagnoses whether the capability is available.
Are scans expensive? And is the product stable?
Scans can be expensive — that's why the cost envelope stops a run once the estimate crosses the ceiling, and estimated cost can differ from final billing. The repository is under active development (0.1.0): interfaces and schemas may change before a stable release, and the gate must be pinned to a versioned reference (@v1), never to @main.
The products that carry the consulting
Okami Agent
Sovereign AI coding agent: capability parity across LLMs, self-improvement (skills, persona, memory) and mandatory design-system adherence. In the terminal, on Telegram, wherever you want.
Okami Monitor
Mission control for multi-agent environments: usage and cost per period, sessions, Kanban, logs, API keys and external runtime connections — in one cockpit.
OkamiCode
Local-first desktop cockpit for AI coding CLIs: folder-bound projects, native sessions per provider, chat, email, Kanban, usage/cost analytics and durable memory — without paying a second API bill.
Okami Maturity
OWASP SAMM v2 maturity assessment: 5 functions, 15 practices, 90 questions — with scorecard, radar, prioritized roadmap and a board-ready PDF report.
Okami Tally
An iPhone panel for your AI subscription quotas — Claude, Codex, Grok, Cursor, Minimax, MiMo and any service with a JSON endpoint. In the app, in widgets, on the Lock Screen and in the Dynamic Island. No backend, no telemetry.
OkTally
Every AI coding subscription quota in your macOS menu bar — Claude Code, Codex, Cursor, OpenRouter and more. Colored pins, a popover with the full picture and a notification before you hit the limit. All local, no telemetry.
OkamiUNI
Email and calendar together on the Mac. Unified inbox, macOS calendars and AI to summarize threads, draft replies and turn emails into appointments. Local data, your choice of AI provider.
Want Okami Sentinel running in your context?
The product is open and you can run it yourself. Rolling it out in your environment, with design-system integration and a documented hand-off, is the consulting.