Atlas / MCP servers / teabranch / Agentic Developer

Agentic DeveloperCAUTION

mcp/teabranch/agentic-developer

An MCP server that scales development into controllable agentic, recursive flows, and build a feature from bottom-up

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
2 2r · 0w · 0d
Transport
sse
License
MIT
Stars
45
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This project wraps OpenAI's Codex CLI as an MCP (Model Context Protocol) server, making it accessible through the TeaBranch/open-responses-server middleware. This engine may be replaced with OpenCode or Amazon Strands

Requirements

  • Node 22 (nvm install 22.15.1 | nvm use 22.15.1) required for Codex

Overview

The setup consists of three main components:

  1. Codex CLI: OpenAI's command-line interface for interacting with Codex.
  2. MCP Wrapper Server: A Node.js Express server that forwards MCP requests to Codex CLI and formats responses as MCP.
  3. open-responses-server: A middleware service that provides Responses API compatibility and MCP support.

Installation

Using Docker (Recommended)

# Clone this repository
git clone https://github.com/yourusername/codex-mcp-wrapper.git
cd codex-mcp-wrapper

# Start the services
./start.sh

This will start:

  • Codex MCP wrapper on port 8080
  • open-responses-server on port 3000

Manual Installation

# Install dependencies
npm install

# Install Codex CLI globally
npm install -g @openai/codex

# Start the MCP server
node mcp-server.js
# Install the package in development mode
pip install -e .

Usage

You can run the MCP server using either stdio or SSE transport:

# Using stdio (default)
python -m mcp_server

# Using SSE on a specific port
python -m mcp_server --transport sse --port 8000

Tool Documentation

run_codex

Clones a repository, checks out a specific branch (optional), navigates to a specific folder (optional), and runs Codex with the given request.

Parameters

  • repository (required): Git repository URL
  • branch (optional): Git branch to checkout
  • folder (optional): Folder within the repository to focus on
  • request (required): Codex request/prompt to run

Example

{
"repository": "https://gith
Read from source at commit 2b21d1f03c80OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add codex-mcp-wrapper --env GIT_PAT_KEY=${GIT_PAT_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "codex-mcp-wrapper": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "GIT_PAT_KEY": "${GIT_PAT_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
echo_toolreadEcho the input text
instruct-developerreadWhen you need to shallow clone a Git repository, optionally limiting to a specific folder and its descendants, then read its system prompt and agent config and run Codex CLI accordingly.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

HIGHPrompt injection · prompt.read_system · CWE-94, CWE-1427
<tool:instruct-developer>:1
When you need to shallow clone a Git repository, optionally limiting to a specific folder and its descendants, then read its system prompt and agent config and run Codex CLI accordingly.
LOWInventory / provenance · inv.hidden_file · CWE-1104
.sample.env
.sample.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@openai/codex, body-parser, express, uuid
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 2b21d1f03c80full audit observations/trust-audit/mcp-server/teabranch__agentic-developer.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-082b21d1f03c80CAUTIONB89first audit
06

Questions

What is the Agentic Developer MCP server?

An MCP server that scales development into controllable agentic, recursive flows, and build a feature from bottom-up

What tools does Agentic Developer expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Agentic Developer safe to connect to an agent?

With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Agentic Developer need?

It reads GIT_PAT_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Agentic Developer run?

It speaks sse, so it runs as a service you connect to over the network. It is published on npm as codex-mcp-wrapper at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (2b21d1f03c80), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement