Agentic DeveloperCAUTION
An MCP server that scales development into controllable agentic, recursive flows, and build a feature from bottom-up
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This project wraps OpenAI's Codex CLI as an MCP (Model Context Protocol) server, making it accessible through the TeaBranch/open-responses-server middleware. This engine may be replaced with OpenCode or Amazon Strands
Requirements
- Node 22 (
nvm install 22.15.1 | nvm use 22.15.1) required for Codex
Overview
The setup consists of three main components:
- Codex CLI: OpenAI's command-line interface for interacting with Codex.
- MCP Wrapper Server: A Node.js Express server that forwards MCP requests to Codex CLI and formats responses as MCP.
- open-responses-server: A middleware service that provides Responses API compatibility and MCP support.
Installation
Using Docker (Recommended)
# Clone this repository git clone https://github.com/yourusername/codex-mcp-wrapper.git cd codex-mcp-wrapper # Start the services ./start.sh
This will start:
- Codex MCP wrapper on port 8080
- open-responses-server on port 3000
Manual Installation
# Install dependencies npm install # Install Codex CLI globally npm install -g @openai/codex # Start the MCP server node mcp-server.js # Install the package in development mode pip install -e .
Usage
You can run the MCP server using either stdio or SSE transport:
# Using stdio (default) python -m mcp_server # Using SSE on a specific port python -m mcp_server --transport sse --port 8000
Tool Documentation
run_codex
Clones a repository, checks out a specific branch (optional), navigates to a specific folder (optional), and runs Codex with the given request.
Parameters
repository(required): Git repository URLbranch(optional): Git branch to checkoutfolder(optional): Folder within the repository to focus onrequest(required): Codex request/prompt to run
Example
{
"repository": "https://gith2b21d1f03c80OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add codex-mcp-wrapper --env GIT_PAT_KEY=${GIT_PAT_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"codex-mcp-wrapper": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"GIT_PAT_KEY": "${GIT_PAT_KEY}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}"
}
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
echo_tool | read | Echo the input text |
instruct-developer | read | When you need to shallow clone a Git repository, optionally limiting to a specific folder and its descendants, then read its system prompt and agent config and run Codex CLI accordingly. |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
When you need to shallow clone a Git repository, optionally limiting to a specific folder and its descendants, then read its system prompt and agent config and run Codex CLI accordingly.
.sample.env
@openai/codex, body-parser, express, uuid
Gates applied: no_behavioural_pass.
2b21d1f03c80full audit observations/trust-audit/mcp-server/teabranch__agentic-developer.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 2b21d1f03c80 | CAUTION | B | 89 | first audit |
Questions
What is the Agentic Developer MCP server?
An MCP server that scales development into controllable agentic, recursive flows, and build a feature from bottom-up
What tools does Agentic Developer expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Agentic Developer safe to connect to an agent?
With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Agentic Developer need?
It reads GIT_PAT_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Agentic Developer run?
It speaks sse, so it runs as a service you connect to over the network. It is published on npm as codex-mcp-wrapper at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (2b21d1f03c80), read on 2026-10-08. The repository is watched and re-audited when it changes.