Oh My CodexSAFE
oh-my-codex (omx) — Orchestration layer for OpenAI Codex CLI. Async Claude Code delegation (no timeouts), structured workflows (autopilot, TDD, code review, planning), persistent state & memory. Like oh-my-zsh but for Codex.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Codex-native orchestration for builders who want one default path from a vague prompt to a durable multi-worker runtime.
OMX v2 is not the old Codex-to-Claude bridge. It is a full Codex product built around:
- durable
.omx/state - tmux-aware team execution
- a real agent catalog
- a plugin SDK plus Codex plugin bridge
- a first-party hook pack for Codex hooks
- CLI, MCP, docs, demos, and packaged assets in one repo
What ships
CLI
omx setup omx doctor omx hud omx team omx explore omx session omx autoresearch omx agents omx plugins omx hooks omx version
Skills
$ultrawork$deep-interview$plan$research$team$review$tdd$doctor$hud$trace$autoresearch$architect$executor$reviewer
MCP families
omx_task_*omx_state_*omx_memory_*omx_note_*omx_explore_*omx_team_*omx_plugin_*omx_hook_*omx_agent_*
Durable contract
.omx/ ├── hud-config.json ├── logs/ ├── memory/ ├── plans/ ├── research/ ├── sessions/ ├── state/ └── team/
Product areas
Runtime
- durable task graph, review queue, inbox, and execution ledger
- tmux-first worker runtime on macOS/Linux, degraded mock mode when tmux is missing
- resumable sessions and persistent team state
Agents
- committed machine-readable catalog for architect, planner, researcher, executor, reviewer, operator
- prompt templates under templates/agents
omx agents list|show|install|validate
Plugins
- local plugin SDK using
.codex-plugin/plugin.json - repo marketplace generation under .agents/plugins/marketplace.json
- first-party bundle at plugins/omx-product
omx plugins init|pack|validate|install-local|list|enable|disable|doctor
cf3f1ff4d88fOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-server -- npx -y @oh-my-codex/[email protected]
{
"mcpServers": {
"mcp-server": {
"command": "npx",
"args": [
"-y",
"@oh-my-codex/[email protected]"
]
}
}
}Exposed tools (54)
35 read · 18 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
omx_agent_get | read | Read one agent definition by id. |
omx_agent_install | write | Install OMX agent prompts into Codex home. |
omx_agent_list | read | List the committed OMX agent catalog. |
omx_agent_validate | write | Validate the committed agent template set. |
omx_explore_diagnostics | write | Run the best available repo diagnostics command. |
omx_explore_diff | read | Read the git diff summary against a base ref. |
omx_explore_files | read | List repository files using the native or ripgrep-backed explorer. |
omx_explore_index | read | Build a repository index by extension and file count. |
omx_explore_refs | read | Find symbol references across the repo. |
omx_explore_rename_preview | write | Preview a rename operation without mutating files. |
omx_explore_replace_preview | read | Preview a search/replace operation without mutating files. |
omx_explore_search | read | Search the repository with ripgrep-backed search. |
omx_explore_symbols | read | Extract symbol anchors for a file. |
omx_explore_tmux | read | Probe tmux availability and version. |
omx_hook_disable | write | Disable a hook preset in repo or personal scope. |
omx_hook_enable | write | Enable a hook preset in repo or personal scope. |
omx_hook_explain | read | Explain a shipped hook preset. |
omx_hook_install | write | Install the OMX first-party hook pack. |
omx_hook_status | read | Read repo/personal hook installation status. |
omx_memory_list | read | List memory namespaces. |
omx_memory_read | read | Read a memory namespace from .omx/memory. |
omx_memory_write | write | Write or merge a memory namespace. |
omx_note_read | read | Read the omnibox note pad. |
omx_note_write | write | Write the omnibox note pad. |
omx_plugin_disable | write | Disable a plugin in Codex config. |
omx_plugin_doctor | read | Report plugin marketplace and config drift. |
omx_plugin_enable | write | Enable a plugin in Codex config. |
omx_plugin_init | read | Scaffold a plugin skeleton under the repo plugins directory. |
omx_plugin_install_local | write | Install a local plugin into the user |
omx_plugin_list | read | List repo marketplace plugins. |
omx_plugin_pack | read | Pack a plugin bundle into a tarball. |
omx_plugin_status | read | Read enabled state for a local plugin. |
omx_plugin_validate | read | Validate a local plugin bundle. |
omx_state_clear | destructive | Delete a mode state file. |
omx_state_list | read | List all active mode states. |
omx_state_read | read | Read a mode state file from .omx/state. |
omx_state_write | write | Write or merge a mode state file under .omx/state. |
omx_task_create | write | Create a durable task in .omx/state/tasks.json. |
omx_task_get | read | Read a task by id. |
omx_task_list | read | List durable tasks by optional status. |
omx_task_update | write | Update task status, owner, notes, or metadata. |
omx_team_await | read | Poll the current team state until a task reaches a terminal stage. |
omx_team_claim | read | Claim a queued task for a worker. |
omx_team_complete | write | Mark a task complete and move it to review. |
omx_team_create | write | Create a durable team runtime. |
omx_team_heartbeat | read | Refresh worker lease/heartbeat status. |
omx_team_inbox | read | Read the durable team inbox. |
omx_team_logs | read | Read worker logs from the durable runtime. |
omx_team_message | write | Push an inbox or system message into the team state. |
omx_team_resume | read | Resume a stopped team runtime. |
omx_team_review | read | Record a review decision for a task. |
omx_team_shutdown | read | Shut down the durable team runtime. |
omx_team_spawn | read | Spawn or attach a worker runtime. |
omx_team_status | read | Read the current team state. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- none-observed
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (7)
omx_state_clear
.app.json
const repoRoot = resolve(sourceDir, "../../..");
const productPluginPath = join(fileURLToPath(new URL("../../..", import.meta.url)), "plugins", "omx-product");@types/node, typescript
@iarna/toml
@modelcontextprotocol/sdk
Gates applied: no_behavioural_pass.
cf3f1ff4d88ffull audit observations/trust-audit/mcp-server/staticpayload__oh-my-codex.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | cf3f1ff4d88f | SAFE | B | 89 | first audit |
Questions
What is the Oh My Codex MCP server?
oh-my-codex (omx) — Orchestration layer for OpenAI Codex CLI. Async Claude Code delegation (no timeouts), structured workflows (autopilot, TDD, code review, planning), persistent state & memory. Like oh-my-zsh but for Codex.
What tools does Oh My Codex expose?
54 in total: 35 read-only, 18 that write, and 1 that can delete or overwrite (omx_state_clear). Every one is listed on this page with its risk.
Is Oh My Codex safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Oh My Codex need?
No credential environment variables were found in its source, so it appears to need none.
How does Oh My Codex run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @oh-my-codex/mcp-server at 2.0.0.
How current is this page?
The grade is for one exact copy of the source (cf3f1ff4d88f), read on 2026-10-08. The repository is watched and re-audited when it changes.