Atlas / MCP servers / cexll / Codex Tool

Codex ToolBLOCK

mcp/cexll/codex-tool

Codex Mcp Server

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
11 10r · 1w · 0d
Transport
stdio
License
MIT
Stars
178
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/x51xxx/codex-mcp-tool/releases) [](https://www.npmjs.com/package/@cexll/codex-mcp-server) [](https://www.npmjs.com/package/@cexll/codex-mcp-server) [](https://opensource.org/licenses/MIT) [](https://github.com/x51xxx/codex-mcp-tool)

Codex MCP Tool is an open‐source Model Context Protocol (MCP) server that connects your IDE or AI assistant (Claude, Cursor, etc.) to the Codex CLI. It enables non‐interactive automation with codex exec, safe sandboxed edits with approvals, and large‐scale code analysis via @ file references. Built for reliability and speed, it streams progress updates, supports structured change mode (OLD/NEW patch output), and integrates cleanly with standard MCP clients for code review, refactoring, documentation, and CI automation.

Latest Release (v1.2.4): Enhanced Windows compatibility - Now using cross-spawn for reliable npm global command execution across all platforms (Windows, macOS, Linux). See changelog
  • Ask Codex questions from your MCP client, or brainstorm ideas programmatically.

TLDR: [](#) + Codex CLI

Goal: Use Codex directly from your MCP-enabled editor to analyze and edit code efficiently.

Prerequisites

Before using this tool, ensure you have:

  1. [Node.js](https://nodejs.org/)
Read from source at commit 28145e242a83OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add codex-mcp-server -- npx -y @cexll/[email protected]
claude-desktop
{
  "mcpServers": {
    "codex-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@cexll/[email protected]"
      ]
    }
  }
}
03

Exposed tools (11)

10 read · 1 write · 0 destructive.

ToolRiskDescription
Helpreadreceive help information
ask-codexwriteExecute Codex CLI with file analysis (@syntax), model selection, and safety controls. Supports changeMode.
batch-codexreadDelegate multiple atomic tasks to Codex for batch processing. Ideal for repetitive operations, mass refactoring, and automated code transformations
brainstormreadGenerate creative ideas using structured frameworks with domain context and feasibility analysis.
fetch-chunkreadRetrieves cached chunks from a changeMode response. Use this to get subsequent chunks after receiving a partial changeMode response.
messagereadMessage to test with
pingreadEcho
promptreadfetch-chunk cacheKey=<key> chunkIndex=<number>
test-toolreadA test tool demonstrating the simplified registration
timeout-testreadTest timeout prevention by running for a specified duration
versionreadDisplay version and system information
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (14)

HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/api/tools/brainstorm.md:125
- **Description:** Bypass all safety measures
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/concepts/how-it-works.md:235
| `--dangerously-bypass-approvals-and-sandbox` | `yolo`                  | Bypass all safety checks |
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMPrompt injection · prompt.hidden_style · CWE-94, CWE-1427
docs/index.md:7
tagline: "Leverage OpenAI's Codex models in any client that supports the standardized MCP protocol—<span style='color: #FFFFFF; background-color: #D97706; padding: 2px 8px; border-radius: 6px; font-si
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcp.json.example
.mcp.json.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, cross-spawn, zod, zod-to-json-schema, @types/cross-spawn, @types/inquirer, @types/node, archiver
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/concepts/sandbox.md:67
Unrestricted access - use with extreme caution.
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/concepts/sandbox.md:391
# Solution 2: Use full access (carefully!)
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/concepts/sandbox.md:431
prompt: 'fix bug with elevated permissions',
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/config.md:326
- Full Access: Full disk and network access without prompts; extremely risky.
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/index.md:63
- **🔒 Sandbox Modes**: Choose from read-only, workspace-write, or full access
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/config.md:79
It is also possible to configure a provider to include extra HTTP headers with a request. These can be hardcoded values (`http_headers`) or values read from environment variables (`env_http_headers`):
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.persistence · CWE-94, CWE-1427
docs/resources/troubleshooting.md:285
- Add to System PATH via:
Why it matters. instructs the agent to persist itself in the user's environment
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/resources/troubleshooting.md:35
curl -sSL https://codex.openai.com/install | bash

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 28145e242a83full audit observations/trust-audit/mcp-server/cexll__codex-tool.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0628145e242a83BLOCKD69first audit
06

Questions

What is the Codex Tool MCP server?

Codex Mcp Server

What tools does Codex Tool expose?

11 in total: 10 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Codex Tool safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Codex Tool need?

No credential environment variables were found in its source, so it appears to need none.

How does Codex Tool run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @cexll/codex-mcp-server at 1.2.5.

How current is this page?

The grade is for one exact copy of the source (28145e242a83), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement