agent-bridge-mcp
An MCP server and HTTP gateway that dispatches coding tasks to Claude Code, Codex, and Antigravity CLI sessions, keeps track of those sessions, and optionally runs an implement → review → verify loop against a real repository.
README
agent-bridge-mcp
An MCP server and HTTP gateway that dispatches coding tasks to Claude Code,
Codex, and Antigravity (agy) CLI sessions, keeps track of those sessions,
and optionally runs an implement → review → verify loop against a real repository.
Status: experimental. This started as a personal orchestration rig and is published in the hope that the session-routing and evidence-gate parts are useful to others. Interfaces will change.
What it does
- Session routing — starts and resumes Claude Code / Codex sessions per project and topic, so follow-up prompts land in the same context.
- Task tracking — every dispatch becomes a task with status, output, and exit code.
- Evidence gate — runs the test commands you specify in a repository and reports whether the change is actually backed by passing tests before you accept it.
- Review loop — dispatches an implementer agent and a reviewer agent in turn, up to a revision limit, gated on the evidence check.
- Gateway — the same capabilities over HTTP + WebSocket, so a remote client (for example a phone) can dispatch work and stream output.
Install
npm install -g @yukinuma/agent-bridge-mcp
Requires Node.js 20+, plus whichever agent CLIs you intend to drive
(claude, codex, and/or agy) already installed and authenticated.
A note on the antigravity agent
agy runs an internal language server and expects a real terminal. Started from an
ordinary pipe it shuts down before it answers, which from the caller's side is
indistinguishable from a hang. On Windows this adapter therefore runs it under
winpty (bundled with Git for Windows) and keeps stdin open for the duration of
the call.
Two consequences worth knowing:
winptyaborts on its own assertion while tearing down, so its exit code does not reflect whatagydid. When running through a pty the adapter judges success by whether a response came back, not by the exit code, and filters the assertion text out of the captured output.- On timeout the process tree is killed by PID. Killing by image name would take out
any interactive
agyyou have open elsewhere, so that is deliberately not done.
Set WINPTY_PATH or AGY_PATH if either binary is somewhere non-standard. On
non-Windows platforms agy is launched directly, which is untested.
Use as an MCP server
{
"mcpServers": {
"agent-bridge": {
"command": "agent-bridge-mcp",
"env": {
"AGENT_BRIDGE_WORKSPACE": "/path/to/your/projects"
}
}
}
}
Tools exposed: agent_send, agent_status, agent_sessions, agent_cancel.
Use as a gateway
export ABC_AUTH_TOKEN="$(openssl rand -hex 24)"
export AGENT_BRIDGE_WORKSPACE="/path/to/your/projects"
agent-bridge-gateway
The gateway refuses to start without ABC_AUTH_TOKEN. There is no default token.
| Variable | Default | Meaning |
|---|---|---|
ABC_AUTH_TOKEN |
(required) | Shared secret for REST and WebSocket auth |
PORT |
3030 |
Listening port |
AGENT_BRIDGE_HOST |
127.0.0.1 |
Bind address |
AGENT_BRIDGE_WORKSPACE |
process.cwd() |
Base directory that project names resolve against |
AGENT_BRIDGE_ROOT |
process.cwd() |
Where session and task state files are written |
AGENT_BRIDGE_ALLOWED_ORIGINS |
localhost only | Comma-separated CORS allowlist |
Endpoints
| Method | Path | Notes |
|---|---|---|
GET |
/api/status |
Gateway and running-task summary |
GET |
/api/projects |
Directories found under the workspace |
GET |
/api/sessions |
List sessions |
GET |
/api/tasks, /api/tasks/:id |
List / inspect tasks |
POST |
/api/dispatch |
Dispatch a task to an agent |
POST |
/api/tasks/:id/cancel |
Cancel a running task |
POST |
/api/evidence |
Run the evidence gate |
POST |
/api/git/commit-push |
Commit and push a repository |
POST |
/api/review-loop |
Run the implement/review loop |
WS |
/ws?token=… |
Task output and lifecycle events |
/api/dispatch, /api/git/commit-push, and /api/review-loop require an explicit
target — either cwd, or a project that resolves inside the workspace. They return
400 rather than falling back to a default directory, and project values that
escape the workspace are rejected.
Security
This service runs coding agents with their safety prompts turned off. That is what makes unattended dispatch work — an agent that stops to ask for approval simply hangs when nobody is at the keyboard — but it means anyone who can reach the API can run arbitrary code as the user running the gateway.
Specifically, the CLI adapters pass:
| Agent | Flag | Opt out |
|---|---|---|
| Codex | --dangerously-bypass-approvals-and-sandbox |
bypassApprovals: false |
| Antigravity | --dangerously-skip-permissions |
bypassPermissions: false |
Both default to bypassing. The opt-outs are adapter-level options; they are not yet plumbed through the MCP tools or the REST API, so over HTTP the bypass is currently unconditional.
Treat this as a privileged local daemon:
- It binds to
127.0.0.1by default. SettingAGENT_BRIDGE_HOSTto anything else exposes task dispatch, sandbox-free code execution, and git push to your network. - The auth token is a single shared secret, sent as a bearer header or a
tokenquery parameter. Query parameters end up in logs — prefer the header where you can. Compromising that one token is equivalent to handing over a shell. - There is no sandboxing between projects beyond the workspace path check.
/api/git/commit-pushpushes to whatever remote the target repository has configured. It does not ask again before pushing.
Do not expose this to an untrusted network, and do not run it as a user with more access than the work actually needs.
Development
npm install
npm run typecheck
npm run build
License
MIT
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。