
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@sealgate/agent-cli-mcp
Advanced tools
SealGate stdio MCP server that runs the Codex and OpenCode coding-agent CLIs headlessly on the local machine.
A thin stdio MCP server that runs a local coding-agent CLI headlessly and
exposes it as a single run tool. It ships two flavors, selected by argument:
| Argument | Wraps | Headless command |
|---|---|---|
codex | OpenAI Codex CLI | codex exec |
opencode | OpenCode CLI | opencode run |
It is designed to be launched on a user's own machine by the SealGate daemon over a stdio tunnel, so the coding agent runs locally (with the user's own CLI auth and config) while every tool call is mediated by the SealGate data firewall.
The wrapped CLI (codex or opencode) must already be installed and
authenticated on PATH on the machine that runs this server. This package does
not install or configure the CLI.
# Wrap the Codex CLI:
npx -y @sealgate/agent-cli-mcp codex
# Wrap the OpenCode CLI:
npx -y @sealgate/agent-cli-mcp opencode
The server speaks MCP over stdio and exposes one tool:
runRun a single headless coding task.
| Field | Type | Required | Description |
|---|---|---|---|
prompt | string | yes | The task or question for the coding agent. |
cwd | string | no | Absolute path to the working directory. Defaults to the daemon's. |
model | string | no | Override the model (passed through to the CLI as-is). |
Progress logs are streamed by the CLI to stderr; the tool returns the CLI's
final output. On a non-zero exit or timeout, isError is set and stdout/stderr
are included for debugging.
| Variable | Default | Description |
|---|---|---|
AGENT_CLI_MCP_TIMEOUT_MS | 1800000 | Per-run timeout in milliseconds. |
shell: false, so no shell is spawned and the
prompt cannot inject shell commands into the launcher.cwd and run commands,
subject to its own sandbox/approval configuration. In the marketplace catalog
the run tool is classified SECRET (write + private-read + untrusted-read)
so the SealGate firewall treats it as maximally sensitive.npm install
npm run build # tsc -> dist/
npm run typecheck
Publishing is automated: pushing a tag agent-cli-mcp-v<version> triggers
.github/workflows/publish-agent-cli-mcp.yaml, which builds and publishes to npm
(requires the NPM_TOKEN repository secret). See that workflow for the first-run
setup.
FAQs
SealGate stdio MCP server that runs the Codex and OpenCode coding-agent CLIs headlessly on the local machine.
The npm package @sealgate/agent-cli-mcp receives a total of 29 weekly downloads. As such, @sealgate/agent-cli-mcp popularity was classified as not popular.
We found that @sealgate/agent-cli-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.