Atlas / MCP servers / robotlearning123 / GPT2Agent

GPT2AgentBLOCK

mcp/robotlearning123/gpt2agent

Your codex login → a full ChatGPT Plus/Pro account (every model, deep research, image gen, code exec) inside Claude Code, Codex & any MCP client. One-line install.

Verdict
BLOCK
Grade
D
Trust score
65 /100
Exposed tools
38 28r · 8w · 2d
Transport
stdio · streamable-http
License
MIT
Stars
50
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MCP server for your ChatGPT account: `codex login` → ChatGPT Plus/Pro inside any MCP client.

An MCP server that puts your ChatGPT Plus or Pro subscription — Chat models and the account-tier features below — inside Claude Code, Codex, Cursor, Windsurf, Zed, and any MCP client.

[](https://pypi.org/project/gpt2agent/) [](https://pepy.tech/projects/gpt2agent) [](https://pypistats.org/packages/gpt2agent) [](https://github.com/robotlearning123/gpt2agent/actions/workflows/ci.yml) [](./LICENSE) [](https://pypi.org/project/gpt2agent/)

📖 Quickstart · Client setup · How it works · Troubleshooting · FAQ · Docs index · Account safety

TL;DR

pipx install gpt2agent        # 1. install
codex login                   # 2. authenticate (or: gpt2agent setup)
gpt2agent install             # 3. register with your MCP client(s), then restart it
gpt2agent doctor              # 4. verify — status table, never spends quota

Then ask your agent to call chat, deep_research, or account_status.

One thing to know up front — conversation tools have three lanes (below): REST needs the sentinel bridge (owner-supplied, not distributed); browser needs a one-time Chrome login; manual works with zero network. Read-only tools work out of the box.

What works right now

September 29 update:

Read from source at commit 43b27312d3ddOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (pypi)
claude mcp add gpt2agent -- None gpt2agent==0.0.26 run --stdio
03

Exposed tools (38)

28 read · 8 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
account_statusreadReturn ChatGPT account info.
agentreadChatGPT Agent Mode — 262K context with autonomous browsing, code
canvas_executewriteExecute code through ChatGPT
chatreadChat with a ChatGPT Chat model exposed by your account.
code_interpreterwriteExecute code via ChatGPT
codex_task_createwriteCreate a new Codex task.
create_automationwriteCreate a scheduled automation (dot recurring work). Defaults to DISABLED.
custom_instructions_getreadReturn ChatGPT custom instructions (PII redacted).
custom_instructions_setdestructiveOverwrite ChatGPT custom instructions (read-modify-write — preserves fields not supplied).
deep_researchreadSearch the web and synthesize a detailed report with citations.
deep_research_heavyreadLong-form Deep Research using gpt-6-pro (5–30 min, uses monthly DR quota — check /backend-api/conversation/init for remaining). For short web-augmented answers use `deep_research` instead.
dot_messagesreadRead the dot conversation (newest last).
dots_statusreadReport whether OpenAI dots (always-on agents) are usable on this account.
generate_imagereadGenerate an image using ChatGPT
get_conversationreadGet full details of a ChatGPT conversation including all messages.
get_file_download_urlreadGet a temporary download URL for a ChatGPT file.
get_file_inforeadGet metadata for a ChatGPT file (images, uploads, etc.).
gpt_chatreadChat through one of your private Custom GPTs.
list_appsreadReturn ChatGPT connected apps/connectors. Names unresolvable — IDs with type classification returned.
list_automationsreadList scheduled automations (the dot
list_codex_envsreadReturn Codex environments (label, repos, network access).
list_codex_tasksreadReturn recent Codex tasks (title + status). Content is PII-redacted.
list_conversationsreadReturn recent ChatGPT conversations (titles PII-redacted).
list_custom_gptsreadList your private Custom GPTs from the ChatGPT sidebar.
list_dotsreadList the account
list_modelsreadList the model catalog exposed by your account.
list_tasksreadReturn scheduled/completed ChatGPT tasks with full metadata (titles PII-redacted).
memory_create_via_chatwriteAdd an entry to your ChatGPT memories.
memory_listreadReturn all ChatGPT memories (PII redacted).
memory_searchreadKeyword search over ChatGPT memories. Returns matching entries (PII redacted).
queue_cancelreadCancel a queued/waiting task. Already-terminal or running tasks
queue_resultreadFetch a finished task
queue_statusreadShow one task (`task_id`) or the whole queue when omitted.
queue_submitwriteEnqueue work on this host
remove_automationdestructiveDelete a scheduled automation (id from `list_automations`).
send_to_dotwriteSend a message to your dot (async delivery; the dot replies later).
set_automation_statuswriteEnable or disable a scheduled automation (id from `list_automations`).
usage_statsreadAccount usage snapshot: per-model caps, per-feature remaining
04

Trust audit

BLOCKgrade D · trust 65/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (3 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (22)

HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
install.sh:87
err "  Debian/Ubuntu:  sudo apt install pipx && pipx ensurepath"
Why it matters. asks for elevated privileges
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
install.sh:88
err "  Fedora:         sudo dnf install pipx && pipx ensurepath"
Why it matters. asks for elevated privileges
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
gpt2agent/sentinel_bridge.py:64
return importlib.import_module(f"wrapper.reverse.{name}")
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
gpt2agent/_vendored/pow.py:408
random.choice(navigator_key),
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
gpt2agent/_vendored/pow.py:409
random.choice(document_key),
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
gpt2agent/_vendored/pow.py:410
random.choice(window_key),
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
gpt2agent/sim.py:400
random.choice(_WINDOW_KEYS),
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_audit_2026_07_09_auth.py:56
token = "eyJhbGciOi.eyJzdWIiOi.c2lnbmF0dXJl"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_audit_2026_07_09_tools.py:127
secret = "sk-ABCDEFGHIJKLMNOPQRST"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_audit_2026_07_09_tools.py:146
api_key = "sk-ABCDEFGHIJKLMNOPQRST"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
custom_instructions_set, remove_automation
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.opencode/goals/state.json.sessions/.migration-v1-complete
.migration-v1-complete
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_browser_all_tools.py:654
src = inspect.getsource(importlib.import_module(modname))
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
gpt2agent/_vendored/pow.py:433
target = bytes.fromhex(diff)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
gpt2agent/_vendored/turnstile.py:50
decoded = base64.b64decode(dx)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
gpt2agent/_vendored/turnstile.py:187
pm[e] = base64.b64decode(_to_str(pm[e])).decode()
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/ci.yml:59
run: sudo apt-get update -qq && sudo apt-get install -y -qq libcurl4-openssl-dev
Why it matters. asks for elevated privileges
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/release.yml:90
run: sudo apt-get update -qq && sudo apt-get install -y -qq libcurl4-openssl-dev
Why it matters. asks for elevated privileges
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, curl_cffi, uvicorn, tomli
Why it matters. 4 requirement(s) not pinned with ==
Fix. pin exact versions
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:73
curl -fsSL https://raw.githubusercontent.com/robotlearning123/gpt2agent/main/install.sh | bash
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/quickstart.md:16
curl -fsSL https://raw.githubusercontent.com/robotlearning123/gpt2agent/main/install.sh | bash
INFOPrompt injection · scope.undeclared_system · CWE-94, CWE-1427
<declared scope>
system use found in code, not declared in the description
Why it matters. the description does not admit a capability the code has
Fix. declare system use in the description, or remove it

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 43b27312d3ddfull audit observations/trust-audit/mcp-server/robotlearning123__gpt2agent.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0843b27312d3ddBLOCKD65first audit
06

Questions

What is the GPT2Agent MCP server?

Your codex login → a full ChatGPT Plus/Pro account (every model, deep research, image gen, code exec) inside Claude Code, Codex & any MCP client. One-line install.

What tools does GPT2Agent expose?

38 in total: 28 read-only, 8 that write, and 2 that can delete or overwrite (custom_instructions_set, remove_automation). Every one is listed on this page with its risk.

Is GPT2Agent safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (65/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does GPT2Agent need?

No credential environment variables were found in its source, so it appears to need none.

How does GPT2Agent run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as gpt2agent.

How current is this page?

The grade is for one exact copy of the source (43b27312d3dd), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement