New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

@sealgate/agent-cli-mcp

Package Overview
Dependencies
Maintainers
1
Versions
7
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@sealgate/agent-cli-mcp

SealGate stdio MCP server that runs the Codex and OpenCode coding-agent CLIs headlessly on the local machine.

Source
npmnpm
Version
0.1.2
Version published
Weekly downloads
17
30.77%
Maintainers
1
Weekly downloads
 
Created
Source

@sealgate/agent-cli-mcp

A thin stdio MCP server that runs a local coding-agent CLI headlessly and exposes it as a single run tool. It ships two flavors, selected by argument:

ArgumentWrapsHeadless command
codexOpenAI Codex CLIcodex exec
opencodeOpenCode CLIopencode run

It is designed to be launched on a user's own machine by the SealGate daemon over a stdio tunnel, so the coding agent runs locally (with the user's own CLI auth and config) while every tool call is mediated by the SealGate data firewall.

Usage

The wrapped CLI (codex or opencode) must already be installed and authenticated on PATH on the machine that runs this server. This package does not install or configure the CLI.

# Wrap the Codex CLI:
npx -y @sealgate/agent-cli-mcp codex

# Wrap the OpenCode CLI:
npx -y @sealgate/agent-cli-mcp opencode

# Pin a default model / reasoning effort at launch (codex shown):
npx -y @sealgate/agent-cli-mcp codex --model gpt-5-codex --effort high

The server speaks MCP over stdio and exposes one tool:

run

Run a single headless coding task.

FieldTypeRequiredDescription
promptstringyesThe task or question for the coding agent.
cwdstringnoAbsolute path to the working directory. When omitted, a fresh temp dir is used.
modelstringnoOverride the model (passed through to the CLI as-is).
effortenumnominimal|low|medium|high reasoning effort. Codex only.

model and effort can also be pinned server-wide at launch, so a marketplace entry sets them once instead of every caller passing them: pass --model <m> / --effort <e> after the agent selector, or set AGENT_CLI_MCP_MODEL / AGENT_CLI_MCP_EFFORT. A per-call run argument overrides the server default; a launch flag overrides the env var. effort is ignored for OpenCode.

Progress logs are streamed by the CLI to stderr; the tool returns the CLI's final output. On a non-zero exit or timeout, isError is set and stdout/stderr are included for debugging.

While a run is in flight the server emits MCP notifications/progress (when the caller supplies a progressToken), carrying the latest stderr line so the call does not look hung. Clients that reset their request timeout on progress stay alive through long reasoning; see the timeout note below.

Timeouts

There are two independent clocks, and they are usually confused:

  • The MCP client's request timeout. The client that calls run decides how long to wait for a response. A headless coding agent can reason for minutes while emitting only stderr, so a client with a short request timeout aborts a perfectly healthy run. This server mitigates that by sending progress heartbeats (above); a client should enable its "reset timeout on progress" behavior (and a generous max total timeout) to benefit. This is the clock that usually fires. Raising AGENT_CLI_MCP_TIMEOUT_MS does not affect it.
  • This server's subprocess cap (AGENT_CLI_MCP_TIMEOUT_MS). A hard ceiling on how long the wrapped CLI may run before it is killed. It is the backstop for a genuinely stuck CLI, not the knob for "the client timed out".

Environment

VariableDefaultDescription
AGENT_CLI_MCP_TIMEOUT_MS1800000Per-run subprocess timeout in milliseconds (hard cap).
AGENT_CLI_MCP_HEARTBEAT_MS10000Interval between progress heartbeats while a run is live.
AGENT_CLI_MCP_MODEL(unset)Server-wide default model; a launch flag or per-call arg wins.
AGENT_CLI_MCP_EFFORT(unset)Server-wide default reasoning effort (codex).

Security notes

  • Arguments are passed as argv with shell: false, so no shell is spawned and the prompt cannot inject shell commands into the launcher.
  • The coding agent itself can read and modify files in cwd and run commands, subject to its own sandbox/approval configuration. In the marketplace catalog the run tool is classified SECRET (write + private-read + untrusted-read) so the SealGate firewall treats it as maximally sensitive.

Development

npm install
npm run build       # tsc -> dist/
npm run typecheck

Publishing is automated: pushing a tag agent-cli-mcp-v<version> triggers .github/workflows/publish-agent-cli-mcp.yaml, which builds and publishes to npm (requires the NPM_TOKEN repository secret). See that workflow for the first-run setup.

Keywords

mcp

FAQs

Package last updated on 04 Sep 2026

Related posts