codex-reasonix-mcp
An MCP bridge that lets Codex supervise Reasonix as an implementation worker in an isolated Git worktree, ensuring safe delegation with scoped writes and sandboxed execution.
README
codex-reasonix-mcp
codex-reasonix-mcp is a security-first MCP bridge that lets Codex supervise
Reasonix as an implementation worker. Codex owns the contract, review, and final
commit decision. Reasonix works in an isolated Git worktree through ACP Goal
mode. The bridge never pushes, merges, or changes the caller's main worktree.
This repository is generic to Git repositories. It contains no Akademi-specific configuration, LLM router, or Codex source modification.
Release status
The current package version is 0.1.0-rc.3. It requires the Reasonix ACP v1
status extension described in the upstream patch.
Until that patch ships in an official Reasonix binary, use a locally built
patched binary and the npm prerelease. Stable v1 will fail closed unless the
binary advertises both required schemaVersion: 1 capabilities.
Requirements
- Node.js 22 or newer
- pnpm 10 for source development
- Git 2.36 or newer (worktrees plus
git hook run) - Linux, macOS, or Windows through WSL; native Windows is rejected
- Reasonix with ACP v1 plus the required status extension
- Bubblewrap on Linux/WSL or Seatbelt on macOS
- A configured Reasonix provider exposing
deepseek-v4-flash
Reasonix, provider credentials, and provider billing remain user-managed. This package neither downloads nor bundles Reasonix.
Install for Codex
Pin the exact bridge version when registering the MCP server:
codex mcp add reasonix-worker -- npx -y codex-reasonix-mcp@0.1.0-rc.3
For development against a locally built Reasonix checkout:
codex mcp add reasonix-worker \
--env REASONIX_BIN=/absolute/path/to/reasonix \
-- npx -y codex-reasonix-mcp@0.1.0-rc.3
Run the non-model diagnostic before delegating work:
npx -y codex-reasonix-mcp@0.1.0-rc.3 doctor
doctor checks Node, Git, platform/WSL, the Reasonix binary and supervisor
flags, ACP extension compatibility, OS sandbox availability, state permissions,
network posture, the required model selector, and the effective session
sandbox. It creates and closes an ACP diagnostic session but never sends a model
prompt.
MCP surface
The server is named reasonix_worker and exposes exactly three tools:
reasonix_delegatevalidates an immutableTaskContractV1, creates the worker branch/worktree/session, and returns while provisioning continues.reasonix_controlsteers, answers an interaction, cancels, finalizes, or closes a task. At most two post-review repair rounds are accepted.reasonix_inspectreturns bounded status, evidence, interactions, events, and optional paginated diffs.
reasonix_delegate and finalization require Codex's
codex/sandbox-state-meta. A writable repository path is derived only from that
metadata; no model-provided repository path is accepted.
Safe lifecycle
- Codex creates a contract with explicit write and forbidden scopes.
- The bridge rejects a dirty source worktree, creates
reasonix/<task-id>, and places the worker worktree below its private state directory. - Reasonix runs Delivery + Goal with planner disabled, scoped writes, sandboxed bash, and network off by default.
- Codex inspects bounded evidence and may request at most two repair rounds.
finalizereruns all verification, rechecks scope/size/secrets, stages explicit files, runs commit hooks against a disposable index, and advances the worker ref only when the resulting tree is byte-for-byte the reviewed tree.- The branch, worktree, contract, and evidence are retained. Nothing is pushed, merged, cherry-picked, or deleted automatically.
See architecture, task contracts, configuration, security, and troubleshooting.
Develop
corepack enable
pnpm install --frozen-lockfile
pnpm check
pnpm audit --audit-level high
CI runs the same gates on Node 22/24 Linux and Node 22 macOS. npm releases use
GitHub OIDC trusted publishing with provenance and no long-lived npm token;
prerelease versions publish under the next dist-tag. See
CONTRIBUTING.md for the release gates.
The offline end-to-end test uses a fake ACP Reasonix agent and performs no live provider calls or external mutations. A live DeepSeek smoke test is intentionally not automated and requires explicit credential and cost authorization.
Community
- Read CONTRIBUTING.md before proposing a change.
- Use the structured bug report or feature request forms for public work.
- Follow the Code of Conduct in all project spaces.
- Report vulnerabilities privately through GitHub Security Advisories, as described in SECURITY.md.
License
MIT. See LICENSE.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。
mcp-server-qdrant
这个仓库展示了如何为向量搜索引擎 Qdrant 创建一个 MCP (Managed Control Plane) 服务器的示例。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。