Codex ToolBLOCK
Codex Mcp Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/x51xxx/codex-mcp-tool/releases) [](https://www.npmjs.com/package/@cexll/codex-mcp-server) [](https://www.npmjs.com/package/@cexll/codex-mcp-server) [](https://opensource.org/licenses/MIT) [](https://github.com/x51xxx/codex-mcp-tool)
Codex MCP Tool is an open‐source Model Context Protocol (MCP) server that connects your IDE or AI assistant (Claude, Cursor, etc.) to the Codex CLI. It enables non‐interactive automation with codex exec, safe sandboxed edits with approvals, and large‐scale code analysis via @ file references. Built for reliability and speed, it streams progress updates, supports structured change mode (OLD/NEW patch output), and integrates cleanly with standard MCP clients for code review, refactoring, documentation, and CI automation.
Latest Release (v1.2.4): Enhanced Windows compatibility - Now using cross-spawn for reliable npm global command execution across all platforms (Windows, macOS, Linux). See changelog
- Ask Codex questions from your MCP client, or brainstorm ideas programmatically.
TLDR: [](#) + Codex CLI
Goal: Use Codex directly from your MCP-enabled editor to analyze and edit code efficiently.
Prerequisites
Before using this tool, ensure you have:
- [Node.js](https://nodejs.org/)
28145e242a83OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add codex-mcp-server -- npx -y @cexll/[email protected]
{
"mcpServers": {
"codex-mcp-server": {
"command": "npx",
"args": [
"-y",
"@cexll/[email protected]"
]
}
}
}Exposed tools (11)
10 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Help | read | receive help information |
ask-codex | write | Execute Codex CLI with file analysis (@syntax), model selection, and safety controls. Supports changeMode. |
batch-codex | read | Delegate multiple atomic tasks to Codex for batch processing. Ideal for repetitive operations, mass refactoring, and automated code transformations |
brainstorm | read | Generate creative ideas using structured frameworks with domain context and feasibility analysis. |
fetch-chunk | read | Retrieves cached chunks from a changeMode response. Use this to get subsequent chunks after receiving a partial changeMode response. |
message | read | Message to test with |
ping | read | Echo |
prompt | read | fetch-chunk cacheKey=<key> chunkIndex=<number> |
test-tool | read | A test tool demonstrating the simplified registration |
timeout-test | read | Test timeout prevention by running for a specified duration |
version | read | Display version and system information |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (14)
- **Description:** Bypass all safety measures
| `--dangerously-bypass-approvals-and-sandbox` | `yolo` | Bypass all safety checks |
tagline: "Leverage OpenAI's Codex models in any client that supports the standardized MCP protocol—<span style='color: #FFFFFF; background-color: #D97706; padding: 2px 8px; border-radius: 6px; font-si
.mcp.json.example
.prettierignore
@modelcontextprotocol/sdk, cross-spawn, zod, zod-to-json-schema, @types/cross-spawn, @types/inquirer, @types/node, archiver
Unrestricted access - use with extreme caution.
# Solution 2: Use full access (carefully!)
prompt: 'fix bug with elevated permissions',
- Full Access: Full disk and network access without prompts; extremely risky.
- **🔒 Sandbox Modes**: Choose from read-only, workspace-write, or full access
It is also possible to configure a provider to include extra HTTP headers with a request. These can be hardcoded values (`http_headers`) or values read from environment variables (`env_http_headers`):
- Add to System PATH via:
curl -sSL https://codex.openai.com/install | bash
Gates applied: instruction_override, no_behavioural_pass.
28145e242a83full audit observations/trust-audit/mcp-server/cexll__codex-tool.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 28145e242a83 | BLOCK | D | 69 | first audit |
Questions
What is the Codex Tool MCP server?
Codex Mcp Server
What tools does Codex Tool expose?
11 in total: 10 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Codex Tool safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Codex Tool need?
No credential environment variables were found in its source, so it appears to need none.
How does Codex Tool run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @cexll/codex-mcp-server at 1.2.5.
How current is this page?
The grade is for one exact copy of the source (28145e242a83), read on 2026-10-06. The repository is watched and re-audited when it changes.