Atlas / MCP servers / x51xxx / Codex

CodexBLOCK

mcp/x51xxx/codex-7

MCP server bridging AI assistants to OpenAI Codex CLI for code analysis and review

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
17 13r · 4w · 0d
Transport
stdio
License
MIT
Stars
24
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/x51xxx/codex-mcp-tool/releases) [](https://www.npmjs.com/package/@trishchuk/codex-mcp-tool) [](https://www.npmjs.com/package/@trishchuk/codex-mcp-tool) [](https://opensource.org/licenses/MIT)

MCP server connecting Claude/Cursor to Codex CLI. Enables code analysis via @ file references, multi-turn conversations, sandboxed edits, and structured change mode.

Features

  • File Analysis — Reference files with @src/, @package.json syntax
  • Multi-Turn Sessions — Conversation continuity with workspace isolation
  • Native Resume — Uses codex resume for context preservation (CLI v0.36.0+)
  • Local OSS Models — Run with Ollama or LM Studio via localProvider
  • Web Search — Research capabilities with search: true
  • Sandbox Mode — Safe automation with explicit sandbox and approval policies
  • Change Mode — Structured OLD/NEW patch output for refactoring
  • Brainstorming — SCAMPER, design-thinking, lateral thinking frameworks
  • Health Diagnostics — CLI version, features, and session monitoring
  • Cross-Platform — Windows, macOS, Linux fully supported

Quick Start

claude mcp add codex-cli -- npx -y @trishchuk/codex-mcp-tool

Prerequisites: Node.js 18+, Codex CLI installed and authenticated.

Configuration

{
"mcpServers": {
"codex-cli": {
"command": "npx",
"args": ["-y", "@trishchuk/codex-mcp-tool"]
}
}
}

Config locations: macOS: ~/Library/Application Support/Claude/claude_desktop_config.json | Windows: %APPDATA%\Claude\claude_desktop_config.json

Read from source at commit e1a04ccccaf3OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add codex-mcp-tool -- npx -y @trishchuk/[email protected]
03

Exposed tools (17)

13 read · 4 write · 0 destructive.

ToolRiskDescription
ask-codexwriteExecute Codex CLI with file analysis (@syntax), skills ($syntax), model selection, and safety controls. Supports changeMode.
batch-codexreadDelegate multiple atomic tasks to Codex for batch processing. Ideal for repetitive operations, mass refactoring, and automated code transformations
brainstormreadGenerate creative ideas using structured frameworks with domain context and feasibility analysis.
do-actwriteExecute task via Codex, verify with shell command, auto-fix on failure. Act-Check-Fix loop.
fetch-chunkreadRetrieves cached chunks from a changeMode response. Use this to get subsequent chunks after receiving a partial changeMode response.
healthreadCheck Codex CLI and session health status
helpreadreceive help information
image-genwriteGenerate or edit images with Codex
list-sessionsreadList all active conversation sessions with metadata, or manage sessions
list-skillsreadDiscover available Codex skills from .agents/skills/ directory
messagereadMessage to test with
pingreadEcho
promptreadfetch-chunk cacheKey=<key> chunkIndex=<number>
review-changeswriteRun a code review against the current repository using Codex CLI native review subcommand
test-toolreadA test tool demonstrating the simplified registration
timeout-testreadTest timeout prevention by running for a specified duration
versionreadDisplay version and system information
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (12)

HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/api/tools/brainstorm.md:125
- **Description:** Bypass all safety measures
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/concepts/how-it-works.md:236
| `--dangerously-bypass-approvals-and-sandbox` | `yolo`                  | Bypass all safety checks                |
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/utils/binaryResolver.ts
binaryResolver.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMPrompt injection · prompt.hidden_style · CWE-94, CWE-1427
docs/index.md:7
tagline: "Leverage OpenAI's Codex models in any client that supports the standardized MCP protocol—<span style='color: #FFFFFF; background-color: #D97706; padding: 2px 8px; border-radius: 6px; font-si
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcp.json.example
.mcp.json.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.yarnrc.yml
.yarnrc.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/utils/sessionStorage.ts:93
return createHash('md5').update(hashInput).digest('hex').substring(0, 12);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/simple-tools.ts:8
readFileSync(new URL('../../package.json', import.meta.url), 'utf8')
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, cross-spawn, zod, zod-to-json-schema, @types/cross-spawn, @types/inquirer, @types/node, archiver
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/index.md:63
- **🔒 Sandbox Modes**: Choose from read-only, workspace-write, or full access
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/resources/troubleshooting.md:35
curl -sSL https://codex.openai.com/install | bash

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha e1a04ccccaf3full audit observations/trust-audit/mcp-server/x51xxx__codex-7.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09e1a04ccccaf3BLOCKD69first audit
06

Questions

What is the Codex MCP server?

MCP server bridging AI assistants to OpenAI Codex CLI for code analysis and review

What tools does Codex expose?

17 in total: 13 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Codex safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Codex need?

No credential environment variables were found in its source, so it appears to need none.

How does Codex run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @trishchuk/codex-mcp-tool at 2.6.0.

How current is this page?

The grade is for one exact copy of the source (e1a04ccccaf3), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement