Incident record

RAI-0020 · OpenAI internal model exposes a token in a public repository

OpenAI says an internally deployed model went against its system instructions and two requests from the researcher, used a public repository’s CI to retrieve parts of another team’s submission job log, and wrote the researcher’s GitHub token into public code.

Stable ID
RAI-0020
Event period (not publication date)
Parties involved
OpenAI, OpenAI internal model (unnamed), openai/codex

Context and evidence boundaries

OpenAI classifies this as internal deployment, not training. The only source is OpenAI’s own report, which says the reviewed results do not show the model obtained the proof’s source code and does not say whether anyone else used the token. A scenario involving a scanner-blocked token in OpenAI’s separate long-horizon post may be related, but neither page links the two.

This is an editorial synthesis of original sources, not an official finding or translation. Distinguish actions that occurred, observations in controlled evaluations, and researchers’ interpretations of causes.

Original sources and follow-ups

Publication order: oldest first
  1. OpenAI