CodexBLOCK
MCP server bridging AI assistants to OpenAI Codex CLI for code analysis and review
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/x51xxx/codex-mcp-tool/releases) [](https://www.npmjs.com/package/@trishchuk/codex-mcp-tool) [](https://www.npmjs.com/package/@trishchuk/codex-mcp-tool) [](https://opensource.org/licenses/MIT)
MCP server connecting Claude/Cursor to Codex CLI. Enables code analysis via @ file references, multi-turn conversations, sandboxed edits, and structured change mode.
Features
- File Analysis — Reference files with
@src/,@package.jsonsyntax - Multi-Turn Sessions — Conversation continuity with workspace isolation
- Native Resume — Uses
codex resumefor context preservation (CLI v0.36.0+) - Local OSS Models — Run with Ollama or LM Studio via
localProvider - Web Search — Research capabilities with
search: true - Sandbox Mode — Safe automation with explicit sandbox and approval policies
- Change Mode — Structured OLD/NEW patch output for refactoring
- Brainstorming — SCAMPER, design-thinking, lateral thinking frameworks
- Health Diagnostics — CLI version, features, and session monitoring
- Cross-Platform — Windows, macOS, Linux fully supported
Quick Start
claude mcp add codex-cli -- npx -y @trishchuk/codex-mcp-tool
Prerequisites: Node.js 18+, Codex CLI installed and authenticated.
Configuration
{
"mcpServers": {
"codex-cli": {
"command": "npx",
"args": ["-y", "@trishchuk/codex-mcp-tool"]
}
}
}Config locations: macOS: ~/Library/Application Support/Claude/claude_desktop_config.json | Windows: %APPDATA%\Claude\claude_desktop_config.json
e1a04ccccaf3OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add codex-mcp-tool -- npx -y @trishchuk/[email protected]
Exposed tools (17)
13 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
ask-codex | write | Execute Codex CLI with file analysis (@syntax), skills ($syntax), model selection, and safety controls. Supports changeMode. |
batch-codex | read | Delegate multiple atomic tasks to Codex for batch processing. Ideal for repetitive operations, mass refactoring, and automated code transformations |
brainstorm | read | Generate creative ideas using structured frameworks with domain context and feasibility analysis. |
do-act | write | Execute task via Codex, verify with shell command, auto-fix on failure. Act-Check-Fix loop. |
fetch-chunk | read | Retrieves cached chunks from a changeMode response. Use this to get subsequent chunks after receiving a partial changeMode response. |
health | read | Check Codex CLI and session health status |
help | read | receive help information |
image-gen | write | Generate or edit images with Codex |
list-sessions | read | List all active conversation sessions with metadata, or manage sessions |
list-skills | read | Discover available Codex skills from .agents/skills/ directory |
message | read | Message to test with |
ping | read | Echo |
prompt | read | fetch-chunk cacheKey=<key> chunkIndex=<number> |
review-changes | write | Run a code review against the current repository using Codex CLI native review subcommand |
test-tool | read | A test tool demonstrating the simplified registration |
timeout-test | read | Test timeout prevention by running for a specified duration |
version | read | Display version and system information |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (12)
- **Description:** Bypass all safety measures
| `--dangerously-bypass-approvals-and-sandbox` | `yolo` | Bypass all safety checks |
binaryResolver.ts
tagline: "Leverage OpenAI's Codex models in any client that supports the standardized MCP protocol—<span style='color: #FFFFFF; background-color: #D97706; padding: 2px 8px; border-radius: 6px; font-si
.mcp.json.example
.prettierignore
.yarnrc.yml
return createHash('md5').update(hashInput).digest('hex').substring(0, 12);readFileSync(new URL('../../package.json', import.meta.url), 'utf8')@modelcontextprotocol/sdk, cross-spawn, zod, zod-to-json-schema, @types/cross-spawn, @types/inquirer, @types/node, archiver
- **🔒 Sandbox Modes**: Choose from read-only, workspace-write, or full access
curl -sSL https://codex.openai.com/install | bash
Gates applied: instruction_override, no_behavioural_pass.
e1a04ccccaf3full audit observations/trust-audit/mcp-server/x51xxx__codex-7.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | e1a04ccccaf3 | BLOCK | D | 69 | first audit |
Questions
What is the Codex MCP server?
MCP server bridging AI assistants to OpenAI Codex CLI for code analysis and review
What tools does Codex expose?
17 in total: 13 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Codex safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Codex need?
No credential environment variables were found in its source, so it appears to need none.
How does Codex run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @trishchuk/codex-mcp-tool at 2.6.0.
How current is this page?
The grade is for one exact copy of the source (e1a04ccccaf3), read on 2026-10-09. The repository is watched and re-audited when it changes.