Atlas / MCP servers / staticpayload / Oh My Codex

Oh My CodexSAFE

mcp/staticpayload/oh-my-codex

oh-my-codex (omx) — Orchestration layer for OpenAI Codex CLI. Async Claude Code delegation (no timeouts), structured workflows (autopilot, TDD, code review, planning), persistent state & memory. Like oh-my-zsh but for Codex.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
54 35r · 18w · 1d
Transport
stdio
License
MIT
Stars
74
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Codex-native orchestration for builders who want one default path from a vague prompt to a durable multi-worker runtime.

OMX v2 is not the old Codex-to-Claude bridge. It is a full Codex product built around:

  • durable .omx/ state
  • tmux-aware team execution
  • a real agent catalog
  • a plugin SDK plus Codex plugin bridge
  • a first-party hook pack for Codex hooks
  • CLI, MCP, docs, demos, and packaged assets in one repo

What ships

CLI

omx setup
omx doctor
omx hud
omx team
omx explore
omx session
omx autoresearch
omx agents
omx plugins
omx hooks
omx version

Skills

  • $ultrawork
  • $deep-interview
  • $plan
  • $research
  • $team
  • $review
  • $tdd
  • $doctor
  • $hud
  • $trace
  • $autoresearch
  • $architect
  • $executor
  • $reviewer

MCP families

  • omx_task_*
  • omx_state_*
  • omx_memory_*
  • omx_note_*
  • omx_explore_*
  • omx_team_*
  • omx_plugin_*
  • omx_hook_*
  • omx_agent_*

Durable contract

.omx/
├── hud-config.json
├── logs/
├── memory/
├── plans/
├── research/
├── sessions/
├── state/
└── team/

Product areas

Runtime

  • durable task graph, review queue, inbox, and execution ledger
  • tmux-first worker runtime on macOS/Linux, degraded mock mode when tmux is missing
  • resumable sessions and persistent team state

Agents

  • committed machine-readable catalog for architect, planner, researcher, executor, reviewer, operator
  • prompt templates under templates/agents
  • omx agents list|show|install|validate

Plugins

  • local plugin SDK using .codex-plugin/plugin.json
  • repo marketplace generation under .agents/plugins/marketplace.json
  • first-party bundle at plugins/omx-product
  • omx plugins init|pack|validate|install-local|list|enable|disable|doctor
Read from source at commit cf3f1ff4d88fOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-server -- npx -y @oh-my-codex/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@oh-my-codex/[email protected]"
      ]
    }
  }
}
03

Exposed tools (54)

35 read · 18 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
omx_agent_getreadRead one agent definition by id.
omx_agent_installwriteInstall OMX agent prompts into Codex home.
omx_agent_listreadList the committed OMX agent catalog.
omx_agent_validatewriteValidate the committed agent template set.
omx_explore_diagnosticswriteRun the best available repo diagnostics command.
omx_explore_diffreadRead the git diff summary against a base ref.
omx_explore_filesreadList repository files using the native or ripgrep-backed explorer.
omx_explore_indexreadBuild a repository index by extension and file count.
omx_explore_refsreadFind symbol references across the repo.
omx_explore_rename_previewwritePreview a rename operation without mutating files.
omx_explore_replace_previewreadPreview a search/replace operation without mutating files.
omx_explore_searchreadSearch the repository with ripgrep-backed search.
omx_explore_symbolsreadExtract symbol anchors for a file.
omx_explore_tmuxreadProbe tmux availability and version.
omx_hook_disablewriteDisable a hook preset in repo or personal scope.
omx_hook_enablewriteEnable a hook preset in repo or personal scope.
omx_hook_explainreadExplain a shipped hook preset.
omx_hook_installwriteInstall the OMX first-party hook pack.
omx_hook_statusreadRead repo/personal hook installation status.
omx_memory_listreadList memory namespaces.
omx_memory_readreadRead a memory namespace from .omx/memory.
omx_memory_writewriteWrite or merge a memory namespace.
omx_note_readreadRead the omnibox note pad.
omx_note_writewriteWrite the omnibox note pad.
omx_plugin_disablewriteDisable a plugin in Codex config.
omx_plugin_doctorreadReport plugin marketplace and config drift.
omx_plugin_enablewriteEnable a plugin in Codex config.
omx_plugin_initreadScaffold a plugin skeleton under the repo plugins directory.
omx_plugin_install_localwriteInstall a local plugin into the user
omx_plugin_listreadList repo marketplace plugins.
omx_plugin_packreadPack a plugin bundle into a tarball.
omx_plugin_statusreadRead enabled state for a local plugin.
omx_plugin_validatereadValidate a local plugin bundle.
omx_state_cleardestructiveDelete a mode state file.
omx_state_listreadList all active mode states.
omx_state_readreadRead a mode state file from .omx/state.
omx_state_writewriteWrite or merge a mode state file under .omx/state.
omx_task_createwriteCreate a durable task in .omx/state/tasks.json.
omx_task_getreadRead a task by id.
omx_task_listreadList durable tasks by optional status.
omx_task_updatewriteUpdate task status, owner, notes, or metadata.
omx_team_awaitreadPoll the current team state until a task reaches a terminal stage.
omx_team_claimreadClaim a queued task for a worker.
omx_team_completewriteMark a task complete and move it to review.
omx_team_createwriteCreate a durable team runtime.
omx_team_heartbeatreadRefresh worker lease/heartbeat status.
omx_team_inboxreadRead the durable team inbox.
omx_team_logsreadRead worker logs from the durable runtime.
omx_team_messagewritePush an inbox or system message into the team state.
omx_team_resumereadResume a stopped team runtime.
omx_team_reviewreadRecord a review decision for a task.
omx_team_shutdownreadShut down the durable team runtime.
omx_team_spawnreadSpawn or attach a worker runtime.
omx_team_statusreadRead the current team state.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
none-observed
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
omx_state_clear
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
plugins/omx-product/.app.json
.app.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/cli/src/context.ts:14
const repoRoot = resolve(sourceDir, "../../..");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/src/index.ts:88
const productPluginPath = join(fileURLToPath(new URL("../../..", import.meta.url)), "plugins", "omx-product");
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@types/node, typescript
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/core/package.json
@iarna/toml
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/mcp-server/package.json
@modelcontextprotocol/sdk
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha cf3f1ff4d88ffull audit observations/trust-audit/mcp-server/staticpayload__oh-my-codex.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08cf3f1ff4d88fSAFEB89first audit
06

Questions

What is the Oh My Codex MCP server?

oh-my-codex (omx) — Orchestration layer for OpenAI Codex CLI. Async Claude Code delegation (no timeouts), structured workflows (autopilot, TDD, code review, planning), persistent state & memory. Like oh-my-zsh but for Codex.

What tools does Oh My Codex expose?

54 in total: 35 read-only, 18 that write, and 1 that can delete or overwrite (omx_state_clear). Every one is listed on this page with its risk.

Is Oh My Codex safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Oh My Codex need?

No credential environment variables were found in its source, so it appears to need none.

How does Oh My Codex run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @oh-my-codex/mcp-server at 2.0.0.

How current is this page?

The grade is for one exact copy of the source (cf3f1ff4d88f), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement