No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by cexll · MCP Server · ★ 178
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is codex-mcp-server safe to install? View the security audit →
Codex MCP Tool Codex MCP Tool is an open‑source Model Context Protocol (MCP) server that connects your IDE or AI assistant (Claude, Cursor, etc.) to the Codex CLI. It enables non‑interactive automation with , safe sandboxed edits with approvals, and large‑scale code analysis via file references. Built for reliability and speed, it streams progress updates, supports structured change mode (OLD/NEW patch output), and integrates cleanly with standard MCP clients for code review, refactoring, documentation, and CI automation. Latest Release (v1.2.4): Enhanced Windows compatibility - Now using cross-spawn for reliable npm global command execution across all platforms (Windows, macOS, Linux). See changelog Ask Codex questions from your MCP client, or brainstorm ideas programmaticall
| Stars | 178 |
| Forks | 14 |
| Language | TypeScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 67.0728735459828/100 |
| Open Issues | 68 |
| Last Updated | 2026-06-06 |
| Created | 2025-10-26 |
| Platforms | codex, mcp, node |
| Est. Tokens | ~17k |
These tools work well together with codex-mcp-server for enhanced workflows:
Explore other popular mcp server tools:
codex-mcp-server is Codex Mcp Server. It is categorized as a MCP Server with 178 GitHub stars.
codex-mcp-server is primarily written in TypeScript.
You can find installation instructions and usage details in the codex-mcp-server GitHub repository at github.com/cexll/codex-mcp-server. The project has 178 stars and 14 forks, indicating an active community.
codex-mcp-server is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: