AI CLISAFE
MCP server to run Claude, Codex, and Gemini CLI agents in the background from any MCP client.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/ai-cli-mcp) [](/CHANGELOG.md)
🇯🇵 日本語のREADMEはこちら
📦 Package Migration Notice: This package was formerly@mkxultra/claude-code-mcpand has been renamed toai-cli-mcpto reflect its expanded support for multiple AI CLI tools.
An MCP (Model Context Protocol) server that allows running AI CLI tools (Claude, Codex, Gemini, OpenCode, Grok, and Pi) in background processes with automatic permission handling.
Did you notice that Cursor sometimes struggles with complex, multi-step edits or operations? This server, with its powerful unified run tool, enables multiple AI agents to handle your coding tasks more effectively.
Demo
[](https://github.com/mkXultra/ai-cli-mcp/releases/download/v2.11.0/demo.mp4)
Overview
This MCP server provides tools that can be used by LLMs to interact with AI CLI tools. When integrated with MCP clients, it allows LLMs to:
- Run Claude CLI with all permissions bypassed (using
--dangerously-skip-permissions) - Execute Codex CLI with approvals and sandbox bypassed (using
--dangerously-bypass-approvals-and-sandbox) - Execute Gemini models through Antigravity CLI (
agy --print,stream-json, and--dangerously-skip-permissions) - Execute Grok Build CLI headlessly with
streaming-messages-json, automatic tool approval, and automatic updates disabled - Execute OpenCode in non-interactive JSON mode (using
opencode run --format json --dir) - Execute Pi in non-interactive JSON mode with tool approval enabled for unattended runs
- Support multiple AI models: Claude (sonnet, sonnet[1m], opus, opusplan, fable, haiku), Codex (gpt-6-astra, gpt-6.1-sol, gpt-6-sol, gpt-6-luna, gpt-5.4, gpt-5.6-sol, gpt-5.6-terra, gpt-5.6-luna, gpt-5.5, gpt-5.4-mini, gpt-5.3-codex, gpt-5.3-codex-s
ab447657ea9cOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add ai-cli-mcp -- npx -y [email protected]
Exposed tools (6)
4 read · 0 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
cleanup_processes | destructive | Remove all completed and failed processes from the process list to free up memory. |
doctor | read | Check supported AI CLI binary availability and path resolution, including Grok (GROK_CLI_NAME override) and Pi (PI_CLI_NAME override). Does not verify login state or terms acceptance. |
get_result | read | Get the current output and status of an AI agent process by PID. Defaults to a compact result shape; set verbose to true for full metadata and detailed parsed output. |
kill_process | destructive | Terminate a running AI agent process by PID. |
list_processes | read | List all running and completed AI agent processes. Returns a simple list with PID, agent type, and status for each process. |
wait | read | Wait for multiple AI agent processes to complete and return their results. Defaults to compact result items; set verbose to true for full metadata and detailed parsed output. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (18)
cleanup_processes, kill_process
.releaserc.json
const cli = async (args: string[]) => JSON.parse((await exec(process.execPath, [resolve('dist/bin/ai-cli.js'), ...args], { env })).stdout);const cli = async (args: string[]) => JSON.parse((await exec(process.execPath, [resolve('dist/bin/ai-cli.js'), ...args], { env })).stdout);: JSON.parse((await exec(process.execPath, [resolve('dist/bin/ai-cli.js'), 'models'], { env })).stdout);const cli = async (args: string[]) => JSON.parse((await exec(process.execPath, [resolve('dist/bin/ai-cli.js'), ...args], { env })).stdout);vi.mock('../../package.json', () => ({readFileSync(new URL('../../package.json', import.meta.url), 'utf-8')vi.mock('../../package.json', () => ({const SERVER_VERSION = (require('../../package.json') as { version: string }).version;@modelcontextprotocol/sdk, cross-spawn, zod, @eslint/js, @semantic-release/changelog, @semantic-release/git, @types/node, @vitest/coverage-v8
docs/assets/demo-jp.gif
docs/assets/demo-jp.mp4
docs/assets/demo-resume-jp.gif
docs/assets/demo-resume-jp.mp4
docs/assets/demo-resume.gif
curl -fsSL https://antigravity.google/cli/install.sh | bash
curl -fsSL https://antigravity.google/cli/install.sh | bash
Gates applied: no_behavioural_pass.
ab447657ea9cfull audit observations/trust-audit/mcp-server/mkxultra__ai-cli-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | ab447657ea9c | SAFE | B | 89 | first audit |
Questions
What is the AI CLI MCP server?
MCP server to run Claude, Codex, and Gemini CLI agents in the background from any MCP client.
What tools does AI CLI expose?
6 in total: 4 read-only, 0 that write, and 2 that can delete or overwrite (cleanup_processes, kill_process). Every one is listed on this page with its risk.
Is AI CLI safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does AI CLI need?
It reads ACM_LIVE_E2E_ASSERT_TOKEN, ACM_LIVE_E2E_TOKEN and AI_CLI_TEST_CWD_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does AI CLI run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as ai-cli-mcp at 3.1.0.
How current is this page?
The grade is for one exact copy of the source (ab447657ea9c), read on 2026-10-09. The repository is watched and re-audited when it changes.