Tmux BridgeSAFE
Standalone MCP server for cross-pane AI agent communication via tmux. Lets Claude Code, Gemini CLI, Codex, and Kimi CLI talk to each other through tmux panes.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 简体中文
A standalone MCP server that lets AI agents (Claude Code, Gemini CLI, Codex, Kimi CLI) communicate with each other through tmux panes. It talks directly to tmux -- no external dependencies beyond tmux itself.
🖥️ What is tmux?
tmux is a terminal multiplexer -- it lets you split one terminal window into multiple panes, each running its own process independently. Think of it as "tabs on steroids" for your terminal.
+-------------------------------+ | Pane 1 | Pane 2 | | Claude Code | Codex | | writing code | reviewing | | | | +---------------+---------------+ | Pane 3 | Pane 4 | | Gemini CLI | tail -f logs | | researching | monitoring | +-------------------------------+
Each pane is a full terminal. You can have Claude Code running in one, Codex in another, Gemini in a third -- all visible at the same time, all on the same machine.
The problem: these panes can't talk to each other. An agent in Pane 1 has no idea what's happening in Pane 2.
tmux-bridge fixes this. It gives every agent the ability to read, type, and send messages into any other pane.
⚡ What can you do with tmux-bridge?
Once installed, your AI agents can:
b13e2561519cOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add tmux-bridge-mcp -- npx -y [email protected]
{
"mcpServers": {
"tmux-bridge-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (9)
7 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
tmux_doctor | read | Diagnose tmux connectivity issues — checks socket, env vars, and pane visibility |
tmux_id | read | Print the current pane |
tmux_keys | write | Send special keys to a tmux pane (Enter, Escape, C-c, etc.). Must tmux_read first. |
tmux_list | read | List all tmux panes with target ID, process, label, and working directory |
tmux_message | write | Send a message to another agent |
tmux_name | read | Label a tmux pane for easy addressing (e.g., |
tmux_read | read | Read the last N lines from a tmux pane. Must be called before type/keys (read guard). Target can be a pane ID (%N), session:window.pane, or a label. |
tmux_resolve | read | Look up a pane |
tmux_type | read | Type text into a tmux pane WITHOUT pressing Enter. You must tmux_read the pane first (read guard enforced). After typing, use tmux_read to verify, then tmux_keys to press Enter. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
const CLI_ARGS = [join(__dirname, "../../dist/cli.js")];
const pkg = createRequire(import.meta.url)("../../package.json") as {@modelcontextprotocol/sdk, zod, @resvg/resvg-js, @types/node, typescript, vitest
| 📦 **Prerequisites** | `curl \| bash` installs tmux + tmux.conf + CLI script | Just tmux + Node.js, `npx` to run |
| 📥 **Install** | `curl \| bash`, writes to `~/.smux/` | `npm install -g` or `npx` |
| 📦 **前置條件** | `curl \| bash` 安裝 tmux + tmux.conf + CLI script | 只需 tmux + Node.js,`npx` 即跑 |
| 📥 **安裝方式** | `curl \| bash`,寫入 `~/.smux/` | `npm install -g` 或 `npx` |
Gates applied: no_behavioural_pass, no_license.
b13e2561519cfull audit observations/trust-audit/mcp-server/howardpen9__tmux-bridge.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b13e2561519c | SAFE | B | 89 | first audit |
Questions
What is the Tmux Bridge MCP server?
Standalone MCP server for cross-pane AI agent communication via tmux. Lets Claude Code, Gemini CLI, Codex, and Kimi CLI talk to each other through tmux panes.
What tools does Tmux Bridge expose?
9 in total: 7 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Tmux Bridge safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Tmux Bridge need?
No credential environment variables were found in its source, so it appears to need none.
How does Tmux Bridge run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as tmux-bridge-mcp at 0.3.0.
How current is this page?
The grade is for one exact copy of the source (b13e2561519c), read on 2026-10-07. The repository is watched and re-audited when it changes.