Define Security Policy: purpose and common use cases
Define Security Policy is cataloged from the official OpenAI Plugins repository as a skill bundled with the codex-security plugin. Artifiner verified its source at plugins/codex-security/skills/define-security-policy/SKILL.md against repository revision 1e285826e604; the page is classified under Security and Developer Tools from source-backed metadata rather than generated ratings or reviews.
Where Define Security Policy fits in an agent workflow
Define Security Policy is a Codex skill for security workflows. Define Security Policy's role is practical rather than generic: it gives an agent task-specific instructions for identifying and validating software risk. In the catalog it is discoverable around security policy, security.md, and threat model, which are useful starting points when the user knows the outcome they need but not the exact capability name. Define Security Policy is bundled with the codex-security plugin, so it should be understood as one capability inside that broader integration rather than as a separate application.
What to check before using Define Security Policy
Use Define Security Policy when the job maps to security review, validation and defensive engineering. For Define Security Policy, a sensible workflow is to start with the task, check that the skill matches the project and tools involved, and then follow the upstream instructions rather than treating the directory description as executable documentation. Artifiner keeps the Define Security Policy source link visible so you can inspect its current SKILL.md before relying on behavior that may change as the repository evolves.
Define or review SECURITY.md guidance, repository security boundaries, threat-model context, and scope for Codex Security.