
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
@ask-llm/claude-mcp
Advanced tools
MCP server for consulting Anthropic Claude Code CLI from Codex and other MCP clients
MCP server for consulting Anthropic Claude Code CLI from Codex CLI, Cursor,
OpenCode, and other MCP clients. It fills the reverse collaboration path:
Claude can ask Codex through @ask-llm/codex-mcp, and Codex can ask Claude through
@ask-llm/claude-mcp.
codex mcp add claude -- npx -y @ask-llm/claude-mcp
Then ask Codex to use ask-claude for an independent review or second opinion.
This provider is for Codex and other non-Claude hosts. Claude Code rejects nested Claude Code sessions; the unified orchestrator automatically suppresses the Claude provider when Claude Code is already the host.
PATH, and authenticated. The implementation is validated
against Claude Code 2.1.206 and requires a version that supports --safe-mode.ask-claude — ask Claude for analysis, with optional native sessionId,
model override, and relative includeDirs.get-usage-stats — in-memory token and duration totals.ping — verify the MCP server and Claude CLI installation.Every consultation runs Claude Code with --safe-mode and an explicit
Read,Glob,Grep tool list. Claude can inspect the current workspace and allowed
relative directories, but cannot run shell commands or modify files. Prompts are
sent through stdin rather than command-line arguments.
opus (override with ASK_CLAUDE_MODEL).sonnet (override with ASK_CLAUDE_FALLBACK_MODEL). Claude Code's
native --fallback-model handles overload or availability failures.ASK_CLAUDE_TIMEOUT_MS, then
GMCPT_TIMEOUT_MS).The tool returns both human-readable text and a structured AskResponse with
the actual model, native Claude session ID, and token usage when the CLI reports
it.
FAQs
MCP server for consulting Anthropic Claude Code CLI from Codex and other MCP clients
We found that @ask-llm/claude-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.