
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
@ask-llm/codex-mcp
Advanced tools
MCP server for OpenAI Codex CLI integration - for Claude IDE and other IDEs
An MCP server for AI-to-AI collaboration via the Codex CLI. Works with Claude Code, Claude Desktop, Cursor, Warp, Copilot, and 40+ other MCP clients. Access GPT-5.5 for code generation, analysis, and review with automatic fallback to GPT-5.4-mini on quota limits.
Part of the Ask LLM monorepo.
claude mcp add codex -- npx -y @ask-llm/codex-mcp
Add to claude_desktop_config.json:
{
"mcpServers": {
"codex": {
"command": "npx",
"args": ["-y", "@ask-llm/codex-mcp"]
}
}
}
{
"command": "npx",
"args": ["-y", "@ask-llm/codex-mcp"]
}
| Tool | Purpose |
|---|---|
ask-codex | Send prompts to Codex CLI. Defaults to GPT-5.6 Sol at medium effort with automatic Terra fallback; optional reasoningEffort override |
ping | Connection test — verify MCP setup without using tokens |
Codex calls are ephemeral when sessionId is omitted. Pass sessionId: "" on the first call to persist a resumable thread, then pass its returned Thread ID on follow-up calls.
| Model | Use Case |
|---|---|
gpt-5.6-sol | Default — flagship capability |
gpt-5.6-terra | Automatic balanced fallback on quota errors |
| Variable | Default | Purpose |
|---|---|---|
ASK_CODEX_MODEL | gpt-5.6-sol | Override the default model |
ASK_CODEX_PREFERRED_MODEL | gpt-5.6-sol | Legacy review-tier escape hatch; only attempted separately when it differs from the default |
ASK_CODEX_FALLBACK_MODEL | gpt-5.6-terra | Override the quota-fallback model |
ASK_CODEX_REASONING_EFFORT | medium | Default reasoning effort (low, medium, high, xhigh, or max); per-call reasoningEffort wins |
ASK_CODEX_LOAD_USER_CONFIG | (unset) | Set to 1 to opt back into loading ~/.codex/config.toml (hooks, MCP servers, preferences) and execpolicy .rules files. By default the wrapper passes --ignore-user-config --ignore-rules so behavior stays deterministic across host machines. Auth credentials in CODEX_HOME always load regardless. See ADR-071. |
ASK_CODEX_TIMEOUT_MS | 800000 | Per-call timeout for the spawned codex process (13.3 min — reasoning models routinely take 5–10 min on substantive prompts; raised in ADR-074) |
GMCPT_TIMEOUT_MS | (unset) | Cross-provider timeout override; lower precedence than ASK_CODEX_TIMEOUT_MS |
GMCPT_LOG_LEVEL | warn | debug, info, warn, or error |
Full docs at lykhoyda.github.io/ask-llm
MIT
FAQs
MCP server for OpenAI Codex CLI integration - for Claude IDE and other IDEs
The npm package @ask-llm/codex-mcp receives a total of 67 weekly downloads. As such, @ask-llm/codex-mcp popularity was classified as not popular.
We found that @ask-llm/codex-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.