Codex Agy Bridge — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Codex Agy Bridge (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Run Antigravity from an agent harness as durable, parallel, human-operable agy sessions over MCP.
<!-- mcp-name: io.github.varadfromeast/codex-agy-bridge -->
codex-agy-bridge wraps the official Antigravity CLI with a resumable MCP control plane. Agent harnesses like Codex, Claude Desktop, or your own GPT/Claude-powered MCP client can start agy runs, wait on sparse events, attach a real terminal, send guarded input, cancel safely, continue exact conversations, and collect final results later by run_id.
Prerequisites:
agy), already authenticated locallyuv / uvxtmux on macOS:brew install tmuxCheck the required commands:
codex --version
agy --version
agy models
uvx --version
tmux -Vagy --version only proves the binary exists. Before adding the MCP server, run agy models; if Antigravity asks you to sign in or reports that you are not logged in, start a visible session and complete the browser/login flow:
agy --prompt-interactive "Authenticate Antigravity and then exit."
agy modelsAfter agy models succeeds, install or restart the MCP server. If a bridge run still hits auth, agy_run_start returns status="auth_required" and opens a visible agy authentication session by default. Complete sign-in there, then start a fresh run. You can also use agy_run_observe(view="terminal") or agy_admin(action="doctor") to inspect the auth-required status.
Install from PyPI with the Codex CLI:
codex mcp add codex-agy-bridge \
--env AGY_CMD="$(command -v agy)" \
-- "$(command -v uvx)" codex-agy-bridge@latestRestart the harness, then verify in Codex if you used the command above:
codex mcp get codex-agy-bridge
codex mcp listRemove it with:
codex mcp remove codex-agy-bridgeFor Claude Desktop or a custom MCP client, use the same stdio command shape: uvx codex-agy-bridge@latest with AGY_CMD set to the authenticated agy executable.
agy runs,each with its own durable state, logs, transcript projection, and result.
tmuxsessions, so Terminal.app can attach without killing the agent.
and the run can still be observed later by run_id.
parallelism, and inspect the whole batch as one coordinated effort.
agy_run_wait blocks on lifecycle, attention,progress, and terminal events without transcript-polling spam.
agy_run_input can reject stale writes when event ortranscript cursors changed after the caller observed the run.
evidence are exposed without private model reasoning.
groups are cancelled safely, and completed result artifacts are preserved.
Help the user install it; do not silently mutate their machine.
command -v codex
command -v agy
command -v uvx
command -v tmux
agy --version
agy modelsagy models reports an auth error, help the user complete the Day 0authentication flow above before adding the MCP server.
codex mcp add codex-agy-bridge \
--env AGY_CMD="$(command -v agy)" \
-- "$(command -v uvx)" codex-agy-bridge@latestcodex mcp get codex-agy-bridge
codex mcp listThe Quick Install command stores an stdio MCP server definition. When the agent harness starts the server, uvx resolves codex-agy-bridge@latest from PyPI, installs it into an isolated cached environment, and runs the codex-agy-bridge console script. AGY_CMD pins the bridge to the user's already-installed and authenticated agy executable.
Do not replace $ or $(...) manually in the command. In POSIX shells, $(command -v agy) and $(command -v uvx) expand to absolute executable paths.
Use this when you want the repository version directly:
codex mcp add codex-agy-bridge \
--env AGY_CMD="$(command -v agy)" \
-- uvx --from git+https://github.com/varadfromeast/codex-agy-bridge \
codex-agy-bridgegit clone https://github.com/varadfromeast/codex-agy-bridge.git
cd codex-agy-bridge
uv sync --extra dev
codex mcp add codex-agy-bridge \
--env AGY_CMD="$(command -v agy)" \
-- uv --directory "$PWD" run codex-agy-bridgeflowchart LR
H["Agent harness<br/>(Codex, Claude, custom MCP client)"]
M["codex-agy-bridge<br/>MCP stdio server"]
S["Durable control plane<br/>runs, goals, events, results"]
W["Detached run supervisor"]
A["Antigravity CLI<br/>agy"]
T["Persistent tmux session<br/>human attach/input"]
L["Local Antigravity<br/>trajectory files"]
H <-->|"MCP tools"| M
M <--> S
S --> W
W --> A
W <--> T
A --> L
W -->|"bounded transcript projection"| S
T -->|"terminal logs and attention prompts"| SThe bridge keeps the MCP server responsive while detached supervisors own the long-running agy processes. State and events are persisted locally, so a run can continue after the original MCP call returns. For the deeper process model, see docs/ARCHITECTURE.md. For the MCP control-loop vision, see docs/MCP_VISION.md.
| Tool | Purpose |
|---|---|
agy_run_start | Start, continue, or open an interactive foreground run |
agy_run_wait | Block until selected runs emit sparse wake events |
agy_run_observe | Read full, status, transcript, or raw terminal views |
agy_run_input | Send input with optional event/transcript preconditions |
agy_run_cancel | Cancel one active run |
agy_run_result | Read final result metadata or bounded result chunks |
agy_goal | Create goals, start targets, and read aggregate status |
agy_admin | Read diagnostics, models, plugins, validation, and changelog |
Typical flow:
agy_run_start -> agy_run_wait -> agy_run_observe -> agy_run_resultUse agy_goal when the harness should split work into named targets with a shared objective and bounded parallelism.
| Variable | Default | Purpose |
|---|---|---|
AGY_CMD | agy on PATH | Exact Antigravity executable |
AGY_BRIDGE_STATE_DIR | ~/.local/state/codex-agy-bridge | Durable run and goal state |
AGY_BRIDGE_AGY_ROOT | ~/.gemini/antigravity-cli | Antigravity conversations and trajectories |
AGY_BRIDGE_MAX_PARALLEL | 50 | Global concurrent-run limit |
AGY_BRIDGE_COMPLETION_STABILITY_SECONDS | 150 | Time a final marker must remain stable |
AGY_BRIDGE_MCP_WAIT_SLICE_SECONDS | 55 | Max seconds a single agy_run_wait MCP call blocks before returning a snapshot so gateways do not time out |
Run state survives MCP server restarts under ~/.local/state/codex-agy-bridge/.
This project is experimental. It currently targets Python 3.11+, macOS, tmux, and Antigravity CLI 1.0.8-compatible commands and trajectory files.
Antigravity is an agentic CLI. It can read and write files, execute commands, and access the network with the current user's privileges. This bridge is not a sandbox or security boundary.
The bridge always enables Antigravity's dangerous permission-skip policy so unattended runs do not stall on CLI approval prompts. Any dangerously_skip_permissions=false input is rejected; the only allowed value is true. sandbox=true and additional_directories are CLI policy hints, not filesystem containment.
The bridge does not read or copy Antigravity OAuth credentials. It invokes the installed agy binary and reads ordinary local conversation metadata and trajectory files.
git clone https://github.com/varadfromeast/codex-agy-bridge.git
cd codex-agy-bridge
uv sync --extra dev
uv run pytest
uv run ruff check .
uv buildRun the server directly:
uv run codex-agy-bridgeThe server uses stdio transport. Do not print diagnostic text to stdout; it would corrupt MCP framing.
A pushed version tag runs .github/workflows/publish.yml, which verifies versions, runs checks, builds distributions, publishes to PyPI through GitHub OIDC, creates a GitHub release, and publishes server.json to the MCP Registry.
The current reader expects Antigravity trajectory JSONL under:
~/.gemini/antigravity-cli/brain/<conversation-id>/
.system_generated/logs/transcript.jsonlIf Antigravity moves to SQLite or a local daemon API, a new adapter can replace this reader without changing the MCP tool contract.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.