Skip to main content
Glama
yuriisamohvalov-creator

codex-cli-sync-mcp

codex-cli-sync-mcp

npm GitHub Packages License: MIT

MCP-сервер, который позволяет Claude Code (или любому другому MCP-клиенту) делегировать выполнение ограниченных задач по написанию кода локальному Codex CLI. Один инструмент — codex_execute — синхронно запускает codex exec --json --skip-git-repo-check --approve-for-me -o <last-message-file> "<task>", дожидается завершения и возвращает компактный отчёт: финальное сообщение модели, git diff --stat, git status --short, код возврата и threadId.

Написан по образцу opencode-v2-mcp/cursor-agent-sync-mcp: один вызов тула блокируется до готового результата. В отличие от них, здесь не было предыдущей рабочей MCP-обёртки для замены — существующая @etheaven/codex-mcp-server построена под устаревший контракт флагов (--full-auto/--ask-for-approval не существуют в установленной codex-cli 0.155.1, вызов с sandbox/fullAuto/approvalPolicy падает с unexpected argument '--full-auto'). Этот сервер вызывает codex exec напрямую актуальными флагами, без слоя трансляции.

Требования

  • Codex CLI, установленный и авторизованный (codex exec --version, codex login/действующий ~/.codex/auth.json).

  • Node.js 18+.

Related MCP server: codex-mcp-server

Установка

Вариант 1 — из npm (рекомендуется)

Пакет опубликован как codex-cli-sync-mcp — полностью публичный, ставится без авторизации:

npm install -g codex-cli-sync-mcp

Вариант 2 — из исходников

git clone git@github.com:yuriisamohvalov-creator/codex-mcp.git ~/tools/codex-mcp
cd ~/tools/codex-mcp
npm install

Вариант 3 — из GitHub Packages

Тот же пакет также зеркалирован в GitHub Packages под именем @yuriisamohvalov-creator/codex-cli-sync-mcp. Важно: в отличие от npmjs.org, GitHub Packages требует аутентификации даже для доступа к пакету (репозиторий приватный) — понадобится .npmrc со scoped-registry и GitHub-токеном с правом read:packages:

# ~/.npmrc или в проекте
echo "@yuriisamohvalov-creator:registry=https://npm.pkg.github.com" >> ~/.npmrc
npm login --registry=https://npm.pkg.github.com --scope=@yuriisamohvalov-creator

npm install -g @yuriisamohvalov-creator/codex-cli-sync-mcp

Подключение к Claude Code

При установке из npm (npm install -g codex-cli-sync-mcp) бинарник уже в PATH:

claude mcp add --scope user codex -- codex-cli-sync-mcp

При установке из исходников:

NODE_BIN="$(which node)"
claude mcp add --scope user codex -- "$NODE_BIN" "$HOME/tools/codex-mcp/server.mjs"

Проверка:

claude mcp get codex
# Status: ✔ Connected

После подключения новой сессии Claude Code (или рестарта текущей) инструмент доступен как mcp__codex__codex_execute.

Важно про имя сервера: если у вас уже была подключена другая MCP-обёртка под именем codex-cli (например, @etheaven/codex-mcp-server), регистрируйте новую под другим именем (как выше — codex), а не переиспользуйте codex-cli. На практике харнесс Claude Code Desktop может закэшировать набор тулов под старым именем сервера и не сбросить кэш даже после нескольких полных рестартов приложения, хотя сам MCP-процесс уже переключился на новый бинарник (дерево процессов это подтверждает). Регистрация под новым именем обходит проблему мгновенно.

Использование инструмента

{
  "task": "Add a slugify() helper in src/lib/slug.ts with tests. Acceptance: kebab-case, trims whitespace. Verify with `npm test -- slug`.",
  "cwd": "/absolute/path/to/project",
  "model": "gpt-5.1-codex",     // опционально
  "timeoutMs": 900000            // опционально, по умолчанию 15 минут
}

Ответ:

{
  "ok": true,
  "exitCode": 0,
  "threadId": "...",
  "text": "...финальное сообщение модели...",
  "diffStat": "...git diff --stat...",
  "statusShort": "...git status --short..."
}

Одобрение команд

По умолчанию используется --approve-for-me — безопасный режим через workspace-write sandbox (файловые правки и команды в пределах рабочей директории без ручного подтверждения). Флаг dangerouslyBypassSandbox переключает на --dangerously-bypass-approvals-and-sandbox — используйте только в средах, уже изолированных снаружи (например, контейнер/VM без доступа к остальной системе).

--approve-for-me и явный -s/--sandbox нельзя комбинировать — codex-cli 0.155.1 отклоняет такой вызов ошибкой; обёртка это учитывает и не передаёт оба одновременно.

Ограничения

  • Одна задача — один синхронный запуск codex exec, без параллелизма в рамках одного вызова инструмента.

  • Долгая задача блокирует вызывающую сессию на всё время выполнения — контролируйте через timeoutMs.

  • Не подменяет ревью: вызывающая сторона должна самостоятельно проверять diffStat/statusShort, а не доверять только полю ok.

Лицензия

MIT

Available Tools

1 tool
codex_executeA

Execute one bounded coding task through Codex CLI (synchronous, blocks until done) and return a compact JSON report with diff/status context.

ParametersJSON Schema
NameRequiredDescriptionDefault
cwdYesAbsolute working directory/repository root.
taskYesBounded coding task with goal, constraints, files, acceptance criteria, and verification command.
modelNoOptional Codex model override, e.g. gpt-5.1-codex.
timeoutMsNoInternal timeout; must be below the MCP client's own per-call timeout.
resumeThreadIdNoResume a specific Codex thread id instead of starting a new one.
dangerouslyBypassSandboxNoUse --dangerously-bypass-approvals-and-sandbox instead of --approve-for-me. Only for environments that are already externally sandboxed.

TDQS

A3.9/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description discloses key behavioral traits: synchronous execution, blocking, and the return of a compact JSON report with diff/status. However, with no annotations present, it does not explicitly mention side effects (e.g., file modifications), permission requirements, failure modes, or sandbox behavior, leaving these to be inferred from the 'coding task' framing and parameter names.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The entire description is a single sentence that front-loads the action and resource, then adds the critical operational detail (synchronous, blocking) and the return type. There is no redundant wording or filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a tool with 6 parameters, no output schema, and no annotations, the description covers the core operation, return format, and blocking behavior. However, it leaves side effects, error handling, and security implications unstated—important for an execution tool—and relies on the `dangerouslyBypassSandbox` parameter to hint at sandboxing. Some gaps remain for high-risk use.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema has 100% description coverage, so all six parameters are already fully documented. The tool description adds no parameter-specific semantics beyond what the schema provides; the phrase 'bounded coding task' mirrors the `task` parameter's own description rather than adding new meaning.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb ('Execute'), a resource ('bounded coding task through Codex CLI'), and the result format ('compact JSON report with diff/status context'). It also clarifies the synchronous blocking behavior, making the tool's purpose unambiguous even without sibling tools to compare against.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives clear context by specifying this is for 'bounded' coding tasks and that it blocks until done. There are no sibling tools to differentiate against, so explicit alternatives or when-not guidance are unnecessary; the 'bounded' qualifier implies the intended scope.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool updatev0.2.0
    • First observedcodex_execute

TDQS

A3.8/5.0

Scored across 1 tool

Disambiguation5/5

With only one tool, there is zero ambiguity in selecting between tools. The purpose is clear and singular.

Naming Consistency5/5

The single tool name follows a clear verb_noun pattern (codex_execute), which is consistent and readable. No conflicting conventions exist.

Tool Count2/5

The server exposes only one tool, which is well below the typical 3-15 range. While the narrow focus may justify a minimal surface, it feels too sparse for a general-purpose coding task executor, especially given the server name suggests broader sync functionality.

Completeness2/5

The server provides only a single execute operation with no supporting tools for status, history, configuration, or cancellation. This leaves significant gaps in the expected lifecycle of a coding task execution service, likely causing agent dead-ends.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers