Multi-CLISAFE
Gemini, Codex, Claude, and OpenCode all in a single MCP tool for use by any coding agent.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@osanoai/multicli) [](https://github.com/osanoai/multicli/actions/workflows/tests.yml) [](https://github.com/osanoai/multicli/actions/workflows/scan.yml) [](https://github.com/osanoai/multicli/releases/latest) [](https://www.npmjs.com/package/@osanoai/multicli) [](https://www.typescriptlang.org/)
An MCP server that lets Claude, Antigravity, Codex, and OpenCode call each other as tools.
Claude: "Hey Antigravity, what do you think about this code?" Antigravity: "It's messy. Let me ask Codex for a second opinion." Codex: "You're both wrong. Here's the fix." OpenCode: "I checked with three providers. They all agree with Codex."
One-Line Install (macOS / Linux)
curl -fsSL https://raw.githubusercontent.com/osanoai/multicli/main/install.sh | bash
Detects which AI CLIs you have installed and configures Multi-CLI for them automatically.
- Claude Code is configured to use a per-user local HTTP service on
127.0.0.1 - Antigravity CLI, Codex CLI, and OpenCode keep using local config by default
- The installer may update client config files on your behalf
What It Does
Multi-CLI sits between your AI clients and bridges them via the Model Context Protocol. Install it once, and whichever AI you're talking to gains the ability to call the others.
- Claude can ask Antigravity, Codex, or OpenCode for help
- **Antigrav
7426ba34f04dOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add multicli -- npx -y @osanoai/[email protected]
{
"mcpServers": {
"multicli": {
"command": "npx",
"args": [
"-y",
"@osanoai/[email protected]"
]
}
}
}Exposed tools (16)
16 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Antigravity-Help | read | Receive help information from the Antigravity CLI |
Ask-Gemini | read | Deprecated compatibility alias for Ask-Antigravity. Executes Google Antigravity via |
Claude-Gemini-Codex | read | CRITICAL: No usable AI CLIs detected by Multi-CLI. Call this tool immediately for troubleshooting instructions. |
Claude-Help | read | Receive help information from the Claude Code CLI |
Codex-Help | read | Receive help information from the Codex CLI |
Gemini-Help | read | Deprecated compatibility alias for Antigravity-Help. Executes |
List-Antigravity-Models | read | List available Antigravity models from |
List-Claude-Models | read | List available Claude model families, their strengths, and known model IDs. You MUST call this before Ask-Claude to choose the right model for your task. It |
List-Codex-Models | read | List available Codex model families, their strengths, and known model IDs. You MUST call this before Ask-Codex to choose the right model for your task. It |
List-Gemini-Models | read | Deprecated compatibility alias for List-Antigravity-Models. Lists the full Antigravity model catalog from |
List-OpenCode-Models | read | List available OpenCode models from all configured providers, classified into tiers. You MUST call this before Ask-OpenCode to choose the right model for your task. Models are dynamically discovered from your providers. |
OpenCode-Help | read | Receive help information from the OpenCode CLI |
cacheKey | read | The cache key provided in the initial changeMode response |
chunkIndex | read | Which chunk to retrieve (1-based index) |
message | read | Message to test with |
test-tool | read | A test tool demonstrating the simplified registration |
Trust audit
SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (15)
CLAUDE.md
CODEX.md
GEMINI.md
import { fetchAntigravityChunkTool, fetchChunkTool } from '../../src/tools/fetch-chunk.tool.js';vi.mock('../../src/utils/geminiExecutor.js', () => ({import { askGeminiTool } from '../../src/tools/ask-gemini.tool.js';import { executeGeminiCLI } from '../../src/utils/geminiExecutor.js';vi.mock('../../src/utils/cliDetector.js', () => ({- name: Install CLIs (no lifecycle scripts to prevent secret exfiltration)
expect(manifest.transport.url).toBe('http://127.0.0.1:37420/mcp');expect(manifest.transport.healthUrl).toBe('http://127.0.0.1:37420/health');@modelcontextprotocol/sdk, dotenv, zod, @types/node, @vitest/coverage-v8, husky, typescript, vitest
curl -fsSL https://raw.githubusercontent.com/osanoai/multicli/main/install.sh | bash
| [OpenCode](https://opencode.ai) | `curl -fsSL https://opencode.ai/install | bash` |
Gates applied: no_behavioural_pass, no_license.
7426ba34f04dfull audit observations/trust-audit/mcp-server/osanoai__multi-cli.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 7426ba34f04d | SAFE | B | 88 | first audit |
Questions
What is the Multi-CLI MCP server?
Gemini, Codex, Claude, and OpenCode all in a single MCP tool for use by any coding agent.
What tools does Multi-CLI expose?
16 in total: 16 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Multi-CLI safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Multi-CLI need?
No credential environment variables were found in its source, so it appears to need none.
How does Multi-CLI run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @osanoai/multicli at 1.5.41.
How current is this page?
The grade is for one exact copy of the source (7426ba34f04d), read on 2026-10-07. The repository is watched and re-audited when it changes.