
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@sealgate/agent-cli-mcp
Advanced tools
SealGate stdio MCP server that runs the Codex and OpenCode coding-agent CLIs headlessly on the local machine.
A thin stdio MCP server that runs a local coding-agent CLI headlessly and
exposes it as a single run tool. It ships two flavors, selected by argument:
| Argument | Wraps | Headless command |
|---|---|---|
codex | OpenAI Codex CLI | codex exec |
opencode | OpenCode CLI | opencode run |
It is designed to be launched on a user's own machine by the SealGate daemon over a stdio tunnel, so the coding agent runs locally (with the user's own CLI auth and config) while every tool call is mediated by the SealGate data firewall.
The wrapped CLI (codex or opencode) must already be installed and
authenticated on PATH on the machine that runs this server. This package does
not install or configure the CLI.
# Wrap the Codex CLI:
npx -y @sealgate/agent-cli-mcp codex
# Wrap the OpenCode CLI:
npx -y @sealgate/agent-cli-mcp opencode
# Pin a default model / reasoning effort at launch (codex shown):
npx -y @sealgate/agent-cli-mcp codex --model gpt-5-codex --effort high
The server speaks MCP over stdio and exposes one tool:
runRun a single headless coding task.
| Field | Type | Required | Description |
|---|---|---|---|
prompt | string | yes | The task or question for the coding agent. |
cwd | string | no | Absolute path to the working directory. When omitted, a fresh temp dir is used. |
model | string | no | Override the model (passed through to the CLI as-is). |
effort | enum | no | minimal|low|medium|high reasoning effort. Codex only. |
model and effort can also be pinned server-wide at launch, so a marketplace
entry sets them once instead of every caller passing them: pass --model <m> /
--effort <e> after the agent selector, or set AGENT_CLI_MCP_MODEL /
AGENT_CLI_MCP_EFFORT. A per-call run argument overrides the server default;
a launch flag overrides the env var. effort is ignored for OpenCode.
Progress logs are streamed by the CLI to stderr; the tool returns the CLI's
final output. On a non-zero exit or timeout, isError is set and stdout/stderr
are included for debugging.
While a run is in flight the server emits MCP notifications/progress
(when the caller supplies a progressToken), carrying the latest stderr line so
the call does not look hung. Clients that reset their request timeout on
progress stay alive through long reasoning; see the timeout note below.
There are two independent clocks, and they are usually confused:
run decides
how long to wait for a response. A headless coding agent can reason for
minutes while emitting only stderr, so a client with a short request timeout
aborts a perfectly healthy run. This server mitigates that by sending
progress heartbeats (above); a client should enable its
"reset timeout on progress" behavior (and a generous max total timeout) to
benefit. This is the clock that usually fires. Raising
AGENT_CLI_MCP_TIMEOUT_MS does not affect it.AGENT_CLI_MCP_TIMEOUT_MS). A hard ceiling
on how long the wrapped CLI may run before it is killed. It is the backstop
for a genuinely stuck CLI, not the knob for "the client timed out".| Variable | Default | Description |
|---|---|---|
AGENT_CLI_MCP_TIMEOUT_MS | 1800000 | Per-run subprocess timeout in milliseconds (hard cap). |
AGENT_CLI_MCP_HEARTBEAT_MS | 10000 | Interval between progress heartbeats while a run is live. |
AGENT_CLI_MCP_MODEL | (unset) | Server-wide default model; a launch flag or per-call arg wins. |
AGENT_CLI_MCP_EFFORT | (unset) | Server-wide default reasoning effort (codex). |
shell: false, so no shell is spawned and the
prompt cannot inject shell commands into the launcher.cwd and run commands,
subject to its own sandbox/approval configuration. In the marketplace catalog
the run tool is classified SECRET (write + private-read + untrusted-read)
so the SealGate firewall treats it as maximally sensitive.npm install
npm run build # tsc -> dist/
npm run typecheck
Publishing is automated: pushing a tag agent-cli-mcp-v<version> triggers
.github/workflows/publish-agent-cli-mcp.yaml, which builds and publishes to npm
(requires the NPM_TOKEN repository secret). See that workflow for the first-run
setup.
FAQs
SealGate stdio MCP server that runs the Codex and OpenCode coding-agent CLIs headlessly on the local machine.
The npm package @sealgate/agent-cli-mcp receives a total of 14 weekly downloads. As such, @sealgate/agent-cli-mcp popularity was classified as not popular.
We found that @sealgate/agent-cli-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.