Run Codex and Cursor as background workers inside Claude Code. Reviews, tasks, and rescues with tracked jobs, live progress, and session handoffs.
MCPpedia last refreshed this data
Agent Collab is an MCP server that run Codex and Cursor as background workers inside Claude Code. Reviews, tasks, and rescues with tracked jobs, live progress, and session handoffs. Its tool list has not been published yet over stdio and sse, requires no API key, and scores 57/100 on MCPpedia's security, maintenance and efficiency rubric.
Config is the same across clients — only the file and path differ.
{
"mcpServers": {
"agent-collab": {
"args": [
"-y",
"@openai/codex"
],
"command": "npx"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
Delegate work from Claude Code to other AI coding agents.
Run this in your terminal to verify the server starts. Then let us know if it worked — your result helps other developers.
npx -y '@openai/codex' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories — click any category to see the underlying evidence.
OpenAI Codex CLI enables code execution through malicious MCP (Model Context Protocol) configuration files
A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a user runs the codex command inside a malicious or compromised repository. Codex automatically loads project-local .env and .codex/config.toml files without requiring user confirmation, allowing attackers to embed arbitrary commands that execute immediately.
>= 0source →Codex has sandbox bypass due to bug in path configuration logic
Due to a bug in the sandbox configuration logic, Codex CLI could treat a model-generated `cwd` as the sandbox’s writable root, including paths outside of the folder where the user started their session. This logic bypassed the intended workspace boundary and enables arbitrary file writes and command execution where the Codex process has permissions - this did not impact the network-disabled sandbox restriction. **Remediation** We released a patch in Codex CLI **0.39.0** that canonicalizes and
Be the first to review
Have you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Others in ai-ml
MCP client bridge: connects to MCP servers and registers their tools on ctx.tools
An autonomous agent that conducts deep research on any data using any LLM providers
1000+ scientific tools for AI scientists: life science, reserach, literature, and more.
Workspace template + MCP server for Claude Code, Codex CLI, Cursor & Windsurf. Multi-agent knowledge engine (ag-refresh / ag-ask) that turns any codebase into a queryable AI assistant.
MCP Security Weekly
Get CVE alerts and security updates for Agent Collab and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.
Delegate work from Claude Code to other AI coding agents.
Run Codex and Cursor as background workers inside Claude Code — reviews, tasks, and rescues with tracked jobs, live progress, and session handoffs.
Quick start • Codex plugin • Cursor plugin • Ambient delegation • Goal plugin • How it works • Development • License
One marketplace, three plugins:
| Plugin | Delegates to | Highlights |
|---|---|---|
codex | OpenAI Codex (codex CLI) | /codex:task, /codex:review, /codex:adversarial-review, /codex:rescue, session transfer, optional stop-review gate. Community fork of openai/codex-plugin-cc with Windows fixes. |
cursor | Cursor (cursor-agent CLI) | /cursor:review, /cursor:task, ownership-verified cancel, WSL support on Windows, resolved-model + token-usage recording. |
goal | Long-horizon goals | /goal:set, /goal:step — one increment per invocation, delegating through the other two plugins, with mechanical state and dispositions. |
The codex and cursor plugins share the same job chassis: background jobs with progress-aware status, stored result output, model recording, resume handoffs into the native tool, and cancel that never kills a process it can't prove it owns.
Add the marketplace in Claude Code:
/plugin marketplace add zebbern/agent-collab
Install any of the plugins:
/plugin install codex@agent-collab
/plugin install cursor@agent-collab
/plugin install goal@agent-collab
Reload, then check readiness:
/reload-plugins
/codex:setup
/cursor:setup
A first run that starts durable work you can collect after restarting Claude:
/codex:task --background --fresh map this repository's architecture and identify the main runtime entrypoints
Copy the returned job ID, close Claude, then reopen the same repository and run:
/codex:status <job-id> --wait
/codex:result <job-id>
For the official OpenAI plugin instead of this fork, use
/plugin marketplace add openai/codex-plugin-cc.
[!IMPORTANT] This is an unofficial fork. It is not built, endorsed, or supported by OpenAI. It is a modified version of openai/codex-plugin-cc at v1.0.6, maintained by @zebbern. Report issues here, not to OpenAI.
EPERM rename semantics, taskkill/tasklist bypass MSYS argument mangling, and the test suite passes on Windows (upstream fails 9 of its own tests there).state.json is written atomically under an exclusive lock; corrupt state/job files are quarantined and rebuilt; terminal jobs can never be resurrected by racing writers./codex:status is progress-aware (file changes, command executions, token usage, likely dead detection); jobs record the model and reasoning effort they ran