Atlas / MCP servers / mkxultra / AI CLI

AI CLISAFE

mcp/mkxultra/ai-cli-1

MCP server to run Claude, Codex, and Gemini CLI agents in the background from any MCP client.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
6 4r · 0w · 2d
Transport
stdio
License
MIT
Stars
27
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/ai-cli-mcp) [](/CHANGELOG.md)

🇯🇵 日本語のREADMEはこちら

📦 Package Migration Notice: This package was formerly @mkxultra/claude-code-mcp and has been renamed to ai-cli-mcp to reflect its expanded support for multiple AI CLI tools.

An MCP (Model Context Protocol) server that allows running AI CLI tools (Claude, Codex, Gemini, OpenCode, Grok, and Pi) in background processes with automatic permission handling.

Did you notice that Cursor sometimes struggles with complex, multi-step edits or operations? This server, with its powerful unified run tool, enables multiple AI agents to handle your coding tasks more effectively.

Demo

[](https://github.com/mkXultra/ai-cli-mcp/releases/download/v2.11.0/demo.mp4)

Overview

This MCP server provides tools that can be used by LLMs to interact with AI CLI tools. When integrated with MCP clients, it allows LLMs to:

  • Run Claude CLI with all permissions bypassed (using --dangerously-skip-permissions)
  • Execute Codex CLI with approvals and sandbox bypassed (using --dangerously-bypass-approvals-and-sandbox)
  • Execute Gemini models through Antigravity CLI (agy --print, stream-json, and --dangerously-skip-permissions)
  • Execute Grok Build CLI headlessly with streaming-messages-json, automatic tool approval, and automatic updates disabled
  • Execute OpenCode in non-interactive JSON mode (using opencode run --format json --dir )
  • Execute Pi in non-interactive JSON mode with tool approval enabled for unattended runs
  • Support multiple AI models: Claude (sonnet, sonnet[1m], opus, opusplan, fable, haiku), Codex (gpt-6-astra, gpt-6.1-sol, gpt-6-sol, gpt-6-luna, gpt-5.4, gpt-5.6-sol, gpt-5.6-terra, gpt-5.6-luna, gpt-5.5, gpt-5.4-mini, gpt-5.3-codex, gpt-5.3-codex-s
Read from source at commit ab447657ea9cOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add ai-cli-mcp -- npx -y [email protected]
03

Exposed tools (6)

4 read · 0 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
cleanup_processesdestructiveRemove all completed and failed processes from the process list to free up memory.
doctorreadCheck supported AI CLI binary availability and path resolution, including Grok (GROK_CLI_NAME override) and Pi (PI_CLI_NAME override). Does not verify login state or terms acceptance.
get_resultreadGet the current output and status of an AI agent process by PID. Defaults to a compact result shape; set verbose to true for full metadata and detailed parsed output.
kill_processdestructiveTerminate a running AI agent process by PID.
list_processesreadList all running and completed AI agent processes. Returns a simple list with PID, agent type, and status for each process.
waitreadWait for multiple AI agent processes to complete and return their results. Defaults to compact result items; set verbose to true for full metadata and detailed parsed output.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
none-observed
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (18)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
cleanup_processes, kill_process
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.releaserc.json
.releaserc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/__tests__/antigravity-surfaces.test.ts:47
const cli = async (args: string[]) => JSON.parse((await exec(process.execPath, [resolve('dist/bin/ai-cli.js'), ...args], { env })).stdout);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/__tests__/grok-surfaces.test.ts:47
const cli = async (args: string[]) => JSON.parse((await exec(process.execPath, [resolve('dist/bin/ai-cli.js'), ...args], { env })).stdout);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/__tests__/model-discovery-surfaces.test.ts:35
: JSON.parse((await exec(process.execPath, [resolve('dist/bin/ai-cli.js'), 'models'], { env })).stdout);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/__tests__/pi-surfaces.test.ts:53
const cli = async (args: string[]) => JSON.parse((await exec(process.execPath, [resolve('dist/bin/ai-cli.js'), ...args], { env })).stdout);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/server.test.ts:50
vi.mock('../../package.json', () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/version-print.test.ts:9
readFileSync(new URL('../../package.json', import.meta.url), 'utf-8')
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/wait.test.ts:50
vi.mock('../../package.json', () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/app/mcp.ts:19
const SERVER_VERSION = (require('../../package.json') as { version: string }).version;
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, cross-spawn, zod, @eslint/js, @semantic-release/changelog, @semantic-release/git, @types/node, @vitest/coverage-v8
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
docs/assets/demo-jp.gif
docs/assets/demo-jp.gif
Why it matters. 1364764 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/assets/demo-jp.mp4
docs/assets/demo-jp.mp4
Why it matters. 7899969 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/assets/demo-resume-jp.gif
docs/assets/demo-resume-jp.gif
Why it matters. 1309040 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/assets/demo-resume-jp.mp4
docs/assets/demo-resume-jp.mp4
Why it matters. 9294016 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/assets/demo-resume.gif
docs/assets/demo-resume.gif
Why it matters. 1186233 bytes not read
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.ja.md:84
curl -fsSL https://antigravity.google/cli/install.sh | bash
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:80
curl -fsSL https://antigravity.google/cli/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha ab447657ea9cfull audit observations/trust-audit/mcp-server/mkxultra__ai-cli-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09ab447657ea9cSAFEB89first audit
06

Questions

What is the AI CLI MCP server?

MCP server to run Claude, Codex, and Gemini CLI agents in the background from any MCP client.

What tools does AI CLI expose?

6 in total: 4 read-only, 0 that write, and 2 that can delete or overwrite (cleanup_processes, kill_process). Every one is listed on this page with its risk.

Is AI CLI safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does AI CLI need?

It reads ACM_LIVE_E2E_ASSERT_TOKEN, ACM_LIVE_E2E_TOKEN and AI_CLI_TEST_CWD_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does AI CLI run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as ai-cli-mcp at 3.1.0.

How current is this page?

The grade is for one exact copy of the source (ab447657ea9c), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement