cos-codex-bridge
Local MCP for Chief of Staff agents to run Codex and Claude Code CLI project sessions with scoped access and durable receipts.
Install / Use
claude mcp add AV-Labs-Co -- npx -y github:AV-Labs-Co/cos-codex-bridgeIf the server publishes to npm under a different name, use that package instead β check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
AutomationSupported Platforms
Our assessment of cos-codex-bridge
cos-codex-bridge scores 83/100 on our quality scale, 1885th of 2,864 Automation skills we index.
Its MCP Server is 15 KB long, well organised into 13 sections with 5 code examples: a thorough specification that gives an agent plenty to work with.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated 5 days ago, so cos-codex-bridge is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit β read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-10-01. It catches known dangerous patterns, not every risk β read a skill before letting an agent act on it.
cos-codex-bridge compared with similar skills
All 4 of these similar skills score higher than cos-codex-bridge; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| cos-codex-bridge (this skill)by AV-Labs-Co | 83 | 3 | 5d ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 87.2k | 16d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.2k | today | CLAUDE.md |
| rufloby ruvnet | 100 | 73.6k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
Frequently asked questions
- How do I install cos-codex-bridge?
- Run
claude mcp add AV-Labs-Co -- npx -y github:AV-Labs-Co/cos-codex-bridge. The install tabs above show the steps for each supported agent. - Which AI agents does cos-codex-bridge work with?
- It is written for Claude Code, Claude Desktop and OpenAI Codex, as a MCP Server file. Other agents that read the same format can often use it too.
- Is cos-codex-bridge safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is cos-codex-bridge still maintained?
- The repository was last updated 5 days ago, so cos-codex-bridge is actively maintained.
Skill content
View source on GitHubCoS Codex Bridge
Your Chief of Staff. Now in charge of Codex, too.

A local MCP server that lets a Chief of Staff client find Codex tasks, create project work, deliver whole prompts, follow progress and continue the same conversation. An optional Claude Code CLI route in the same MCP does this with local project folders and saved CLI sessions. Free MIT core. No bridge subscription or checkout. Your existing Codex or Claude Code access is required for real execution.
Choose your release: 0.1.4 on npm is the stable Codex-only route (@latest). 0.2.0-beta.1 adds Claude Code CLI support (@beta) in the same MCP. Install locally, connect your client, then use the bridge_* tools. No daemon or Desktop-owner adapter installation is required. The Codex core workflow and the Grok Bot β Claude Code CLI handoff have passed owner field testing on macOS. Desktop-owned paused-queue recovery remains a known Codex limitation. Sidebar rendering on newer Codex Desktop versions is not certified; check the compatibility table before relying on it. A queued receipt is never proof that work started.
The bridge is indexed in the official MCP Registry and Glama. These are discovery listings; the bridge still installs and runs locally.
What your Chief of Staff can do
- Turn research or a product idea into a new Codex project and task.
- Send the complete prompt and attached text without manual copying and pasting.
- Find an existing Codex task, read its progress and continue the same conversation.
- Track delivery with durable receipts instead of assuming an accepted prompt ran.
- Rename, assign, pin and cancel scoped work across approved projects.
- Keep local project access inside explicit allowlisted directories.
Example: βCreate a project for this idea, send my research to Codex, monitor the build, and follow up in the same task with the review findings.β
Claude Code route (beta)
The same MCP can now start and continue Claude Code CLI work. Pass provider:"claude-code" to bridge_projects, bridge_sessions and bridge_submit; the existing Codex route remains the default. A local folder is the Claude Code project context. The bridge creates a saved CLI session there, returns a durable receipt, reads its result and follows up in the same session. This was locally tested with Claude Code 2.1.269, including a real file edit in a disposable folder.
In an owner field test, the Grok Bot Chief of Staff used the installed MCP to create an allowlisted folder, send a prompt to Claude Code, read its completion, and follow up in the same saved session. Both bridge receipts and Claude Code's native session history were checked. This proves the local CLI handoff, not Claude Desktop or account Project control.
Claude account Projects, ordinary chats, Cowork/Dispatch and Desktop-owned sessions are separate surfaces. This route does not create or control them, and a CLI session does not automatically appear in Claude Desktop's sidebar. Claude setup, exact workflow and limits.
See the handoff
<p align="center"> <img src="docs/assets/cos-codex-bridge-demo.webp" width="360" alt="Animated illustration of a Grok Bot Chief of Staff sending work through CoS Codex Bridge to Codex"> </p>The animation illustrates the local handoff. It uses no private Desktop data or project screenshots.
Try the safe demo
New here? Start with the no-account quickstart. It uses the stable npm package, needs no Git clone, and shows what a completed receipt looks like. Report your install result, including which local MCP client you use.
This exercises the MCP workflow locally without a Codex account, model call or project changes:
This clone uses GitHub main, currently the Claude Code CLI preview (0.2.0-beta.1). To demo the stable Codex-only source instead, run git checkout v0.1.4 after cd cos-codex-bridge and before npm ci.
git clone https://github.com/AV-Labs-Co/cos-codex-bridge.git
cd cos-codex-bridge
npm ci
npm run demo
The demo prints a completed receipt, payload hash and task metadata so you can see the bridge contract before granting access to a real project.
Easiest setup: give this link to your local assistant
Open the repository and installation instructions. An assistant with local terminal access can install it for you. A browser-only or cloud-only chat cannot install software on your computer.
Copy this installation request to your Chief of Staff:
Install CoS Codex Bridge from https://github.com/AV-Labs-Co/cos-codex-bridge. Read the README and SECURITY.md first. Use only a project folder I approve, keep read-only defaults, and preserve existing client configuration. Follow the installer instructions, run doctor, and connect the generated stdio MCP entry to my local client. Tell me what passed and what still needs setup. Wait for my first task before submitting any work. Do not publish or deploy anything.
You can also download the source archive from Releases, extract it and follow the steps below. Git cloning makes later updates easier. A public npm package is available, but no hosted endpoint is required.
Install
Requires Node.js 22+, npm, a locally authenticated Codex CLI for Codex work and/or Claude Code CLI for Claude work, and a local client supporting stdio MCP. Codex Desktop registration additionally requires Codex Desktop on macOS.
The Git clone below installs the current main branch, which is the Claude Code CLI preview (0.2.0-beta.1). For the stable Codex-only source, run git checkout v0.1.4 immediately after cd cos-codex-bridge, before npm ci. The pinned npm @0.1.4 command below is the stable package route.
git clone https://github.com/AV-Labs-Co/cos-codex-bridge.git
cd cos-codex-bridge
npm ci
npm test
node scripts/install.mjs --root /absolute/path/to/your/projects
The installer writes a private config, launcher and MCP snippet under ~/.local/share/cos-codex-bridge. Keep the checkout in place. Default execution is read-only; use --write only for approved project edits. Choose specific project roots, never your entire home directory. Add --codex /absolute/path/to/codex or --claude /absolute/path/to/claude if either CLI is not on the MCP client's PATH. See installer and upgrade steps.
If you prefer npm to Git, install a pinned release into a dedicated folder, then run its same local installer. Use @0.1.4 for stable Codex only or @0.2.0-beta.1 for Codex plus the Claude Code CLI preview:
mkdir -p "$HOME/.local/share/cos-codex-bridge-package"
npm install --prefix "$HOME/.local/share/cos-codex-bridge-package" cos-codex-bridge@0.1.4
node "$HOME/.local/share/cos-codex-bridge-package/node_modules/cos-codex-bridge/scripts/install.mjs" --root "/absolute/path/to/your/projects"
Keep that package folder: the generated launcher points to it. The npm path was checked with clean stable and beta installs, isolated demo configs and doctor. The installer does not edit any MCP client settings for you.
~/.local/share/cos-codex-bridge/cos-codex-bridge doctor
Check codexAvailable, claudeCodeAvailable, claudeCodeAuthenticated, mode, sandbox and roots. The Claude sign-in check is made from the MCP host's process and may differ from a sandboxed terminal; doctor does not verify Desktop sidebar rendering. For a model-free demo, install into a separate prefix with --demo.
Paste the generated mcp-client.json into your client's MCP configuration. Equivalent shape:
{"mcpServers":{"cos-codex-bridge":{"command":"/absolute/path/to/node","args":["/absolute/path/to/cos-codex-bridge/dist/cli.js","--config","/absolute/path/to/config.json","mcp"]}}}
A complete handoff
Tell your Chief of Staff: βFind my app project, send this entire implementation brief to Codex, monitor it, then continue that same task with the review findings.β
- Resolve the exact project and task with
bridge_projectsandbridge_sessions. - Create a directory if needed, then register it. A directory alone is not a Desktop project.
- Call
bridge_submitwithproject, the wholeprompt, and a stablerequestId. IncludethreadIdfor follow-ups. - Poll
bridge_receipt. Verify hashes, task ID and eventual completion. Handle clarification withbridge_answer. - Use
bridge_session_manageto rename, assign or pin the task. Stored metadata and visible Desktop rendering are separate proofs.
A successful model completion does not independently prove that generated code works. Review and test the result.
Ten tools, twelve features and one known limitation
| Tool | Purpose |
|---|---|
| bridge_projects | List aliases, create a folder, register/open or inspect a Desktop project |
| bridge_sessions | Find and read existing allowed tasks, including externally created tasks |
| bridge_submit | Start or follow up; stable request IDs and complete UTF-8 payloads |
| bridge_receipt | Durable progress, hashes, bounded output and explicit uncertainty |
| bridge_steer | Retry recovery of an existing bridge queue item, without resending it |
| bridge_answer | Answer pending clarification; never approve permission expansion |
| bridge_cancel | Request cancellation of bridge-owned direct work |
| bridge_artifact | Read/write versioned text artifacts without overwrite |
| bridge_session_manage | Rename, pin/unpin and assign to a registered project |
| bridge_doctor | Report mode, Codex version, scope and honest capability limits |
Known limitation (uncommon): If a session already has an active writer and a steering prompt is sent, the prompt waits for a natural pause/stopping point. On a long autonomous run, the only human intervention needed is pressing Steer in that case.
See the v1 capability contract and verification matrix.
Busy tasks, steering and interruption recovery
Direct submission defaults to SESSION_BUSY when another writer owns the task. To opt into the existing Desktop execution policy, use onBusy:"queue" and acceptDesktopPolicy:true. delivery:"desktop-queue" explicitly queues to an existing task. These paths use Codex's first-party queue API, the equivalent of codex queue, and preserve separate text inputs and stable client message IDs.
Receipts distinguish busy, queued, steered, delivered, completed, blocked and uncertain. `thread/queue/
Truncated for display β read the full file on GitHub.
Related Skills
Agent-Reach
87.2kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu β one CLI, zero API fees.
headroom
74.2kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.6kπ The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
CowAgent
47.2kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit β see the Safety scan above for what the skill file itself contains.
