Atlas / MCP servers / razzant / Claudexor

ClaudexorCAUTION

mcp/razzant/claudexor

Multi-harness control plane for Claude Code, Codex, Cursor, and OpenCode: quota-aware rotation across multiple Claude/Codex subscriptions, shared thread context, and cross-model review.

Verdict
CAUTION
Grade
F
Trust score
55 /100
Exposed tools
22 12r · 10w · 0d
Transport
stdio
License
MIT
Stars
493
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/claudexor) [](https://www.npmjs.com/package/claudexor) [](https://github.com/razzant/claudexor/releases) [](https://github.com/razzant/claudexor/releases) [](https://github.com/razzant/claudexor/stargazers) [](https://github.com/razzant/claudexor/releases/latest) [](LICENSE)

Website

Claudexor is a local-first control plane for the AI coding agents you already pay for. It runs Codex CLI, Claude Code, Cursor CLI, OpenCode, Antigravity CLI, and raw API adapters behind one typed interface: a chat of turns where read-only questions resume the vendor's own native session, write turns land as inspectable patches or complete file manifests, races pit harnesses against each other with cross-family review, and every claim — cost, quota, web evidence, auth route — is a typed fact you can audit, never a vibe.

Compared to driving a bare Codex or Claude Code session, Claudexor adds the layer the vendors do not ship: best-of-N races with independent reviewers and arbitration; honest budget/quota accounting (unknown cost is never $0); deterministic gates and protected paths; and — since 2.1 — credential profiles: named Antigravity/Claude/Codex/Cursor subscription bindings side by side, each with Claudexor-scoped state and platform-declared credential custody. Live subscription-quota tracking — and

Read from source at commit 84e86ab81e82OBSERVED · 2026-10-02
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add claudexor -- npx -y [email protected] mcp serve
03

Exposed tools (22)

12 read · 10 write · 0 destructive.

ToolRiskDescription
Last-Event-IDreadResume cursor sent on reconnect: ${cursorSemantics}. Omit to snapshot-then-subscribe from the beginning.
claudexor_accountsreadReturn the read-only Accounts view: registered profiles, readiness, quota freshness, and routing identity.
claudexor_answer_interactionwriteAnswer a daemon-persisted run interaction; success is reported only after the control API acknowledges the journal mutation.
claudexor_apply_checkwriteDry-check whether a run
claudexor_capabilitiesreadReturn the derived AgentCapabilityCatalog: per-harness live capabilities (doctor-backed), canonical modes, the mutability matrix, run-control keys, CLI verbs, and the run-apply-state vocabulary.
claudexor_inspectwriteInspect a daemon-tracked run: status, summary, decision verdict, and the derived applyEligibility (what unblocks apply).
claudexor_journal_recoveryreadInspect, validate, or export one durable journal partition through v2.
claudexor_quarantine_journalwriteQuarantine a corrupt partition and start a fresh epoch after exact confirmation.
claudexor_run_cancelwriteRequest cancellation of a daemon-owned run; success is returned only after the control API acknowledges the durable command.
claudexor_run_interactionswriteList daemon-persisted questions that are still awaiting answers for a run.
claudexor_run_resultwriteRead a durable run
claudexor_run_statuswriteRead the current daemon-acknowledged state of a durable Claudexor run.
claudexor_runsreadList recent daemon-tracked Claudexor runs (recovery: find a lost runId).
claudexor_statusreadstatus
claudexor_thread_readreadRead a thread
claudexor_thread_turnreadEnqueue a turn on a persistent Claudexor thread with optional routing and strict account overrides. Supply idempotencyKey to recover a lost response without creating another paid turn. Returns durable thread and turn handles plus runId or a queued jobId.
credentialProfileIdreadPin a managed profile; omitted selects the engine
cursorreadOpaque keyset cursor from a prior page
lastEventIdwriteCompatibility alias for the Last-Event-ID header (same numeric run
limitwriteMaximum run summaries to return (1..1000; default 200). The page is newest-first by (createdAt, id).
pathreadAbsolute visible (non-hidden) directory under the server user
repoRootreadScope the trust-state listing to a single repository root (absolute path); omit to list all.
04

Trust audit

CAUTIONgrade F · trust 55/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (6 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/cli/src/credential-commands.ts:496
for (const secret of result.secrets) print(`${secret.name} [${secret.backend}]`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/macos/ClaudexorApp/Sources/ClaudexorApp/AppModel+Remote.swift:529
baseURL: URL(string: "http://127.0.0.1:\(forward.localPort)")!,
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/macos/ClaudexorApp/Sources/ClaudexorApp/RemoteViews.swift:250
url: URL(string: "http://127.0.0.1:\(request.localPort)")!)
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/cli/src/claudexord-zombie-writer-lease.test.ts:289
token: "issue-159-zombie-owner",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/cli/src/cli-council.test.ts:133
token: "council-http-fixture",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/cli/src/credential-commands.test.ts:148
const token = "profile-login-setup-fixture";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/cli/src/daemon-recovery-integration.test.ts:131
const token = "recovery-integration-token";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/control-api/src/addressed-run-read.test.ts:23
const TOKEN = "addressed-run-read-token";
LOWInventory / provenance · inv.binary · CWE-1104
apps/macos/ClaudexorKit/Tests/ClaudexorKitTests/Fixtures/remote-runtime-update/canonical-signing-bytes.bin
canonical-signing-bytes.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.node-version
.node-version
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
site/.nojekyll
.nojekyll
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
benchmarks/terminal_bench/scripts/colima-setup.sh:41
log "      ln -sf \"\$(brew --prefix)/opt/docker-compose/bin/docker-compose\" ~/.docker/cli-plugins/docker-compose"
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
benchmarks/terminal_bench/scripts/colima-setup.sh:47
log "      ln -sf \"\$(brew --prefix)/opt/docker-buildx/bin/docker-buildx\" ~/.docker/cli-plugins/docker-buildx"
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
packages/cli/src/remote-filesystem.test.ts:49
writeFileSync(join(root, "id_ed25519"), "PRIVATE KEY");
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
packages/cli/src/remote-filesystem.test.ts:141
writeFileSync(join(project, "id_ed25519"), `${opensshKeyHeader}\nabc`);
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
packages/cli/src/remote-filesystem.test.ts:144
for (const path of [".env", ".git/config", "id_ed25519", "notes.txt"]) {
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
benchmarks/swe-bench/scripts/_common.sh:9
CLAUDEXOR_REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../../.." && pwd)"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
benchmarks/terminal_bench/scripts/_common.sh:10
CLAUDEXOR_REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../../.." && pwd)"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/cli/src/claudexord-belt-entry.test.ts:155
const smoke = resolve(import.meta.dirname, "../../../scripts/smoke-delegation-belt-entry.mjs");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/cli/src/claudexord-zombie-writer-lease.test.ts:227
const repoRoot = resolve(import.meta.dirname, "../../..");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/cli/src/cli-council.test.ts:7
import { Orchestrator } from "../../orchestrator/src/orchestrator.js";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/macos/ClaudexorApp/Tests/ClaudexorAppTests/AccountsPresentationTests.swift:197
baseURL: URL(string: "http://127.0.0.1:1234")!, token: "test")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/macos/ClaudexorApp/Tests/ClaudexorAppTests/AppModelRefreshTests.swift:11
baseURL: URL(string: "http://127.0.0.1:1234")!, token: "test"

Gates applied: no_behavioural_pass.

Audited 2026-10-02 · audit v0.4.1 · source sha 84e86ab81e82full audit observations/trust-audit/mcp-server/razzant__claudexor.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0284e86ab81e82CAUTIONF55first audit
06

Questions

What is the Claudexor MCP server?

Multi-harness control plane for Claude Code, Codex, Cursor, and OpenCode: quota-aware rotation across multiple Claude/Codex subscriptions, shared thread context, and cross-model review.

What tools does Claudexor expose?

22 in total: 12 read-only, 10 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Claudexor safe to connect to an agent?

With care. The audit graded it F (55/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Claudexor need?

It reads AGENT_CLI_CREDENTIAL_STORE, ANTHROPIC_API_KEY, CLAUDEXOR_ANTHROPIC_API_KEY, CLAUDEXOR_CODEX_API_KEY, CLAUDEXOR_CURSOR_API_KEY, CLAUDEXOR_DISABLE_STORED_SECRETS, CLAUDEXOR_RAWAPI_KEY, CLAUDE_CODE_OAUTH_TOKEN, CODEX_API_KEY, CURSOR_API_KEY, GITHUB_TOKEN and MY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Claudexor run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @claudexor/workspace at 3.17.2.

How current is this page?

The grade is for one exact copy of the source (84e86ab81e82), read on 2026-10-02. The repository is watched and re-audited when it changes.

Advertisement