MCP servers that let Claude Code delegate to other coding CLIs (Copilot, Codex, Gemini) for cross-model second opinions, structured reviews, and multi-engine consultations.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.AGY_PATHCODEX_BRIDGE_BINCODEX_BRIDGE_MAX_OUTPUT_CHARSCODEX_BRIDGE_MODELCODEX_BRIDGE_SANDBOX— read-only read-only, workspace-write, or danger-full-access. Also overridable per call via the sandbox argument.CODEX_BRIDGE_TIMEOUTCONSULT_MAX_OUTPUT_CHARS— 50000 Total output truncation capCONSULT_MODE— all Default mode (all or first)CONSULT_ORDER— copilot,codex,agy Default engine orderCONSULT_PER_ENGINE_CHARS— 20000 Per-engine truncation in all modeCONSULT_TIMEOUT— 300 Per-engine timeout in secondsCOPILOT_BRIDGE_BINCOPILOT_BRIDGE_MAX_OUTPUT_CHARSCOPILOT_BRIDGE_MODELCOPILOT_BRIDGE_PERM_ARGS— (restrictive defaults) Replace permission flags wholesale. JSON array or whitespace-separated string. Deny rules always beat allow rules in Copilot.COPILOT_BRIDGE_TIMEOUT[](https://m8ven.ai/mcp/hydr0nefn-claude-bridges-13vkd1)