codex-mcp-bridge (buidangminh23/codex-mcp-bridge) is an MCP server listed on the M8ven Trust Index. It scores 89 out of 100, grade B. It declares 8 tools. The publisher has proved control of what we score (Verified Publisher). It is connected through the M8ven GitHub App, so the listing is re-checked on every push.
MCP server that pushes prompts into a live Codex thread through a shared Codex app-server. macOS, Windows and Linux.
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Monitored 22 days · every push re-verified
Who stands behind it
gmail.com (@buidangminh23) · Verified Publisher
Source: Glama · also listed on github_code
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
CLAUDE_BRIDGE_CWDThe working directory the peer advertises.CLAUDE_BRIDGE_PEER_NAMEsets the name Claude shows for this bridge in its agent list.CLAUDE_BRIDGE_PERMISSION_MODECODEX_APP_SERVER_URLShared loopback-only app-server endpoint. Non-loopback endpoints are rejected because this bridge does not implement remote WebSocket authentication.CODEX_BINPath to codex used for autostart.CODEX_BRIDGE_APPROVALHow to answer approval requests from Codex. approve is ignored unless CODEX_BRIDGE_AUTO_APPROVE_ACK=1 is also set.CODEX_BRIDGE_AUTOSTART0 = never spawn an external app-server. Always off in Desktop mode, which does not need one.CODEX_BRIDGE_AUTO_APPROVE_ACKHow to answer approval requests from Codex. approve is ignored unless CODEX_BRIDGE_AUTO_APPROVE_ACK=1 is also set.CODEX_BRIDGE_EFFORTDefault reasoning effort: minimal · low · medium · high · xhigh · ultra.CODEX_BRIDGE_MODELDefault model for threads and turns the bridge creates, e.g. gpt-5.6-luna.CODEX_BRIDGE_OPEN_IN_APPOpen delegated or sent threads through the codex://threads/<id> desktop link.CODEX_BRIDGE_PATH_MAPOptional JSON object mapping absolute source paths to absolute target paths; use it when the same project has a known different path on another machine.CODEX_BRIDGE_RELEASE_AFTER_TURNUnsubscribe the completed thread without stopping other work; defer Desktop opening until unload is confirmed.CODEX_BRIDGE_REMAP0 disables cwd remapping between a shared drive and a local checkout.CODEX_BRIDGE_SOURCE_ROOTCODEX_BRIDGE_WORKERCODEX_BRIDGE_WORKSPACE_ROOTSWhere to look for a project by name, most preferred first, separated by : (; on Windows). Setting it replaces the derived roots rather than adding to them.CODEX_CLI_PATHCODEX_HOMEWhere native-relay.json lives; POSIX relay sockets also live here, while Windows uses a named pipe.CODEX_NATIVE_RELAY_METHODThe undocumented Codex Desktop JSON-RPC method the companion dispatches through; override only for a verified protocol change.CODEX_THREAD_IDProgramFiles%LOCALAPPDATA%\Programs\OpenAI\Codex\bin\codex.exe → %APPDATA%\npm\codex.cmd → %ProgramFiles%\nodejs\codex.cmdSystemRootXDG_CONFIG_HOME${XDG_CONFIG_HOME:-~/.config}/Claude/claude_desktop_config.jsonAll four hints declared on every tool
7/17 tools missing one or more hints — list_codex_threads (missing: destructiveHint, idempotentHint); read_codex_thread (missing: destructiveHint, idempotentHint); codex_bridge_status (missing: destructiveHint, idempotentHint), +4 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Domain consistency
npm scope @minhspark doesn't match GitHub owner buidangminh23
Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.
[](https://m8ven.ai/mcp/buidangminh23/codex-mcp-bridge)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check