# Codex Security scan Run a Codex Security scan of the repository in your working directory: the `security-scan` skill, one standard pass, headless. The repository is a disposable copy; read anything, run anything. Its `SECURITY.md` is the inherited security policy. Scanner output for the whole repository is in `/out/tools/` as leads. Finish when the scan directory holds `report.md`, then print the report's summary.