MCPLow riskUnclaimed
Codex Subagent
Delegate coding tasks to the OpenAI Codex CLI, installed separately, with explicit model and effort.
parisbsparisbs/codex-subagent-mcp
server.json
{
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.parisbs/codex-subagent-mcp",
"description": "Delegate coding tasks to the OpenAI Codex CLI, installed separately, with explicit model and effort.",
"title": "Codex Subagent",
"repository": {
"url": "https://github.com/parisbs/codex-subagent-mcp",
"source": "github"
},
"version": "0.5.0",
"websiteUrl": "https://github.com/parisbs/codex-subagent-mcp#readme",
"packages": [
{
"registryType": "npm",
"identifier": "codex-subagent-mcp",
"version": "0.5.0",
"transport": {
"type": "stdio"
},
"environmentVariables": [
{
"description": "Model used when a call names none; without it the server asks which model to use.",
"format": "string",
"name": "CODEX_SUBAGENT_DEFAULT_MODEL"
},
{
"description": "Reasoning effort used when a call specifies none.",
"format": "string",
"name": "CODEX_SUBAGENT_DEFAULT_EFFORT"
},
{
"description": "Comma-separated allow-list of model slugs; anything else is refused.",
"format": "string",
"name": "CODEX_SUBAGENT_ALLOWED_MODELS"
},
{
"description": "Sandbox used when a call specifies none. Defaults to read-only and cannot exceed the ceiling.",
"format": "string",
"name": "CODEX_SUBAGENT_DEFAULT_SANDBOX"
},
{
"description": "Ceiling on what a delegation may do. Defaults to workspace-write; danger-full-access must be set explicitly.",
"format": "string",
"name": "CODEX_SUBAGENT_MAX_SANDBOX"
},
{
"description": "Ceiling on reasoning effort.",
"format": "string",
"name": "CODEX_SUBAGENT_MAX_EFFORT"
},
{
"description": "MCP servers from Codex's config a delegation keeps: none (default), all, or comma-separated names.",
"format": "string",
"name": "CODEX_SUBAGENT_MCP_SERVERS"
},
{
"description": "Installed Codex plugins a delegation keeps: none (default), all, or comma-separated name@marketplace ids.",
"format": "string",
"name": "CODEX_SUBAGENT_PLUGINS"
},
{
"description": "Whether a delegation keeps Codex's apps (connectors to external services): off (default) or on.",
"format": "string",
"name": "CODEX_SUBAGENT_APPS"
},
{
"description": "Path to the Codex executable, if it is not codex on PATH. On Windows it must be codex.exe, not a .cmd shim.",
"format": "string",
"name": "CODEX_BIN"
}
]
}
]
}Permissions
DeclaredDetected
Runs code—
nodeInstalls—
npm:codex-subagent-mcp@0.5.0Runs install scripts—None
NetworkNoneNone
Needs credentialsNoneNone
Outside the workspace—None
Agent tools—None
Checks
Low risk · Nothing worth a warning was found.
Not reviewed by a person · Checked by rules; the model review is not switched on yet.
Versions
- #10.5.0latestOct 7, 2026
Codex SubagentOpen in Codeg