ArmorCodex
Intent-based security governance for OpenAI Codex and ChatGPT. Register intent plans before tool calls, apply natural-language policy rules, and get per-request audit logs across all your AI agents.
README
ArmorCodex
ArmorIQ intent-based security enforcement for OpenAI Codex. ArmorCodex asks Codex to declare a Bash execution plan before it runs commands, checks each Bash command against that plan and local policy, and optionally sends signed intent and audit events to ArmorIQ IAP.
Current Codex Harness
ArmorCodex is built for the current Codex hook harness documented by OpenAI:
- Hooks are discovered from
~/.codex/hooks.jsonand<repo>/.codex/hooks.json. - Hooks require
[features] hooks = truein~/.codex/config.toml. PreToolUse,PermissionRequest, andPostToolUsecurrently emitBashonly.- Non-Bash tools such as MCP, file edits, web search, and write/apply-patch are not directly intercepted by Codex hooks today.
Treat ArmorCodex as a strong Bash guardrail and audit layer, not a complete boundary for every Codex capability.
See Codex harness limitations for the harness gaps that need to be addressed before ArmorCodex can claim broader tool coverage.
Sources: OpenAI Codex hooks docs and plugin build docs: https://developers.openai.com/codex/hooks https://developers.openai.com/codex/plugins/build
How It Works
User Prompt -> UserPromptSubmit -> intent-plan directive
|
Codex calls register_intent_plan MCP tool
|
Bash command -> PreToolUse -> policy + intent verification -> allow/deny
Approval request -> PermissionRequest -> policy approval gate
Bash result -> PostToolUse -> audit log to ArmorIQ IAP
Install
From This Checkout
npm install
chmod +x install_armorcodex.sh
./install_armorcodex.sh
The installer enables hooks, installs the Codex plugin through the ArmorIQ marketplace, and can install the repo hook file globally when run from this checkout.
Manual Repo-Local Setup
npm install
mkdir -p ~/.codex
printf '\n[features]\nhooks = true\n' >> ~/.codex/config.toml
Then run Codex from this repository. The repo-local hook file is already at .codex/hooks.json.
Manual MCP Setup
ArmorCodex ships a Codex plugin manifest at .codex-plugin/plugin.json and an MCP server config at .mcp.json. The MCP server exposes:
register_intent_planpolicy_readpolicy_update
Configuration
Core environment variables:
| Variable | Default | Description |
|---|---|---|
ARMORCODEX_MODE |
enforce |
enforce blocks failures; monitor logs only |
ARMORCODEX_INTENT_REQUIRED |
true |
Require a registered intent plan before Bash |
ARMORCODEX_DATA_DIR |
~/.codex/armorcodex |
Runtime, policy, and pending-plan storage |
ARMORCODEX_DEBUG |
false |
Debug logs on stderr |
ARMORIQ_API_KEY |
from ~/.armoriq/credentials.json |
ArmorIQ backend key |
ARMORCODEX_AUDIT_ENABLED |
true when API key exists | Send audit logs |
ARMORCODEX_CRYPTO_POLICY_ENABLED |
false |
Enable Merkle policy binding |
Policy Commands
Structured armor commands (staged: nothing applies until you confirm):
Type these as plain prompts with no leading slash:
armor policy list, not/armor. Codex reserves/for its own built-in commands, so ArmorCodex intercepts thearmor ...text in theUserPromptSubmithook.
armor policy listandarmor policy viewarmor policy add deny bash(orallow/hold; multiple:add allow bash and apply_patch, deny apply_patch)armor policy remove <id>armor policy resetarmor policy default deny|allow|hold(unmatched-tool default)armor policy template <all-allow|lockdown|strict-read-only|balanced>armor profile save|list|switch|delete <name>armor mcp approve|deny <server>andarmor mcp listarmor yes/armor noto apply or discard the staged change
Staging a change shows a diff and risk warnings; applying is human-only (the MCP policy_command tool can read and stage, but only a terminal armor yes applies). See POLICY_GUIDE.md.
Natural-language commands still work for quick edits (applied immediately):
Policy list,Policy get <id>,Policy delete <id>,Policy resetPolicy new: deny Bash for payment dataPolicy update <id>: allow BashPolicy prioritize <id> <position>
Tests
cd plugins/armorcodex
npm test
Repository Structure
armorCodex/
├── .codex/hooks.json # Repo-local Codex hook registration
├── .codex-plugin/plugin.json # Codex plugin manifest
├── .mcp.json # ArmorCodex MCP server config
├── hooks/hooks.json # Plugin-local hook reference
├── scripts/
│ ├── bootstrap.mjs # Lazy dependency installer and dispatcher
│ ├── hook-router.mjs # Codex hook router
│ ├── policy-mcp.mjs # MCP server
│ └── lib/ # Policy, intent, IAP, crypto, runtime modules
└── tests/
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。