Atlas / MCP servers / osanoai / Multi-CLI

Multi-CLISAFE

mcp/osanoai/multi-cli

Gemini, Codex, Claude, and OpenCode all in a single MCP tool for use by any coding agent.

Verdict
SAFE
Grade
B
Trust score
88 /100
Exposed tools
16 16r · 0w · 0d
Transport
stdio · streamable-http
License
—
Stars
75
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@osanoai/multicli) [](https://github.com/osanoai/multicli/actions/workflows/tests.yml) [](https://github.com/osanoai/multicli/actions/workflows/scan.yml) [](https://github.com/osanoai/multicli/releases/latest) [](https://www.npmjs.com/package/@osanoai/multicli) [](https://www.typescriptlang.org/)

An MCP server that lets Claude, Antigravity, Codex, and OpenCode call each other as tools.

Claude:      "Hey Antigravity, what do you think about this code?"
Antigravity: "It's messy. Let me ask Codex for a second opinion."
Codex:       "You're both wrong. Here's the fix."
OpenCode:    "I checked with three providers. They all agree with Codex."

One-Line Install (macOS / Linux)

curl -fsSL https://raw.githubusercontent.com/osanoai/multicli/main/install.sh | bash

Detects which AI CLIs you have installed and configures Multi-CLI for them automatically.

  • Claude Code is configured to use a per-user local HTTP service on 127.0.0.1
  • Antigravity CLI, Codex CLI, and OpenCode keep using local config by default
  • The installer may update client config files on your behalf

What It Does

Multi-CLI sits between your AI clients and bridges them via the Model Context Protocol. Install it once, and whichever AI you're talking to gains the ability to call the others.

  • Claude can ask Antigravity, Codex, or OpenCode for help
  • **Antigrav
Read from source at commit 7426ba34f04dOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add multicli -- npx -y @osanoai/[email protected]
claude-desktop
{
  "mcpServers": {
    "multicli": {
      "command": "npx",
      "args": [
        "-y",
        "@osanoai/[email protected]"
      ]
    }
  }
}
03

Exposed tools (16)

16 read · 0 write · 0 destructive.

ToolRiskDescription
Antigravity-HelpreadReceive help information from the Antigravity CLI
Ask-GeminireadDeprecated compatibility alias for Ask-Antigravity. Executes Google Antigravity via
Claude-Gemini-CodexreadCRITICAL: No usable AI CLIs detected by Multi-CLI. Call this tool immediately for troubleshooting instructions.
Claude-HelpreadReceive help information from the Claude Code CLI
Codex-HelpreadReceive help information from the Codex CLI
Gemini-HelpreadDeprecated compatibility alias for Antigravity-Help. Executes
List-Antigravity-ModelsreadList available Antigravity models from
List-Claude-ModelsreadList available Claude model families, their strengths, and known model IDs. You MUST call this before Ask-Claude to choose the right model for your task. It
List-Codex-ModelsreadList available Codex model families, their strengths, and known model IDs. You MUST call this before Ask-Codex to choose the right model for your task. It
List-Gemini-ModelsreadDeprecated compatibility alias for List-Antigravity-Models. Lists the full Antigravity model catalog from
List-OpenCode-ModelsreadList available OpenCode models from all configured providers, classified into tiers. You MUST call this before Ask-OpenCode to choose the right model for your task. Models are dynamically discovered from your providers.
OpenCode-HelpreadReceive help information from the OpenCode CLI
cacheKeyreadThe cache key provided in the initial changeMode response
chunkIndexreadWhich chunk to retrieve (1-based index)
messagereadMessage to test with
test-toolreadA test tool demonstrating the simplified registration
04

Trust audit

SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (15)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWInventory / provenance · inv.symlink · CWE-1104
CLAUDE.md
CLAUDE.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
CODEX.md
CODEX.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
GEMINI.md
GEMINI.md
Why it matters. link not followed
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/tools/fetchChunk.test.ts:2
import { fetchAntigravityChunkTool, fetchChunkTool } from '../../src/tools/fetch-chunk.tool.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/tools/geminiAlias.test.ts:3
vi.mock('../../src/utils/geminiExecutor.js', () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/tools/geminiAlias.test.ts:8
import { askGeminiTool } from '../../src/tools/ask-gemini.tool.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/tools/geminiAlias.test.ts:9
import { executeGeminiCLI } from '../../src/utils/geminiExecutor.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/tools/initTools.test.ts:3
vi.mock('../../src/utils/cliDetector.js', () => ({
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
.github/workflows/refresh-catalog.yml:30
- name: Install CLIs (no lifecycle scripts to prevent secret exfiltration)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/service.test.ts:79
expect(manifest.transport.url).toBe('http://127.0.0.1:37420/mcp');
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/service.test.ts:80
expect(manifest.transport.healthUrl).toBe('http://127.0.0.1:37420/health');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, dotenv, zod, @types/node, @vitest/coverage-v8, husky, typescript, vitest
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:24
curl -fsSL https://raw.githubusercontent.com/osanoai/multicli/main/install.sh | bash
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:69
| [OpenCode](https://opencode.ai) | `curl -fsSL https://opencode.ai/install | bash` |

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha 7426ba34f04dfull audit observations/trust-audit/mcp-server/osanoai__multi-cli.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-077426ba34f04dSAFEB88first audit
06

Questions

What is the Multi-CLI MCP server?

Gemini, Codex, Claude, and OpenCode all in a single MCP tool for use by any coding agent.

What tools does Multi-CLI expose?

16 in total: 16 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Multi-CLI safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Multi-CLI need?

No credential environment variables were found in its source, so it appears to need none.

How does Multi-CLI run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @osanoai/multicli at 1.5.41.

How current is this page?

The grade is for one exact copy of the source (7426ba34f04d), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement