Hydra
Enables Codex to delegate bounded engineering jobs to Claude Code CLI in isolated Git worktrees with strict security and allowance pacing.
README
Hydra
Run bounded Claude Code jobs from Codex without handing over your repository or your release process.
Hydra is a local Codex plugin that sends a specific engineering task to the Claude Code CLI already signed in on your Mac. Jobs run in the background. Write access stays inside isolated Git worktrees. Codex remains responsible for checking the result and deciding what reaches your branch.
Hydra uses your Claude.ai Pro or Max subscription. It rejects API credentials, provider gateways, and automatic model fallback.
Why Hydra exists
A fresh agent pays for context again. Three broad mid-tier sessions can consume more input and cache tokens than one focused Opus session that settles the question.
Hydra makes that cost visible and starts with one lead by default. It opens another session only for a separate scope, an unresolved question, or an independent judgment that the plan names in advance. Each session receives a bounded evidence capsule and a small role-specific delta instead of the host conversation.
What it provides
| Concern | Hydra's rule |
|---|---|
| Authentication | Use the installed Claude Code CLI and an existing Claude.ai Pro or Max login. |
| Model choice | Request Sonnet, Opus, Fable, or a full Claude model ID explicitly. Never fall back. |
| Fan-out | Start with one lead. Permit at most three fresh sessions and one Fable session per plan. |
| Writes | Run test and execute jobs in dedicated detached Git worktrees. |
| Network | Use a strict empty allowlist for sandboxed write jobs. |
| Persistence | Keep bounded, sanitized events and immutable terminal results on disk. |
| Cancellation | Signal only identity-matching process groups, then escalate from SIGTERM to SIGKILL. |
| Allowance | Pace manual usage snapshots; preserve quality floors and reject paid overflow. |
Install
Hydra 1.0 supports macOS on Apple silicon. You need Node.js 20.9 or newer, Git, Codex, and Claude Code 2.1.228 or newer.
git clone https://github.com/azixxxxx/Hydra.git
cd Hydra
npm ci
npm run check
codex plugin marketplace add "$PWD"
codex plugin add hydra@hydra-local
Open a new Codex task after installation so it discovers the MCP server and bundled skills.
First run
Start with preflight. It checks the local CLI version, Claude.ai authentication, provider routing, and the capabilities Hydra relies on.
Run Hydra preflight for this repository.
Then ask for a bounded job:
Ask Opus for an independent architecture review of the persistence layer. Limit the evidence capsule to the relevant files and return repository references for every finding.
Hydra exposes nine MCP tools for preflight, routing, starting jobs, status, paginated results, continuation, cancellation, outcome recording, and allowance snapshots. See the plugin reference for request shapes and operating details.
How it fits together
flowchart LR
Codex["Codex"] -->|"MCP request"| Server["Hydra server"]
Server --> Store["Durable job store"]
Store --> Worker["Detached worker"]
Worker -->|"explicit model and effort"| Claude["Claude Code CLI"]
Worker --> Worktree["Isolated Git worktree"]
Claude --> Worker
Worker --> Store
Server -->|"status and bounded results"| Codex
The server returns immediately after it creates a durable job and launches its worker. The worker survives an MCP restart, records sanitized evidence, and preserves useful worktrees for inspection. Hydra never commits, pushes, merges, deploys, or applies a patch to your main checkout.
Allowance pacing
Hydra records manual snapshots from Claude Settings as integer basis points. It does not scrape the account page, call private usage endpoints, or pretend that local token counts equal a weekly quota percentage.
During most of the week, Hydra conserves optional work. Inside the final 24 hours, it can spend verified surplus more aggressively, but only when it has enough matching observations, the snapshot is fresh, the job is useful, and every applicable bucket still fits its reserve. Required model and effort never decrease to save allowance.
The account-level usage-credit switch remains a manual check. Keep usage credits disabled if paid overflow must be impossible. If Claude asks for credits, Hydra stops with USAGE_CREDITS_REQUIRED rather than switching models or billing paths.
Security boundary
Hydra removes external setting sources, hooks, project MCP servers, automatic memory, WebFetch, and WebSearch from delegated jobs. Read permissions are scoped to the repository or worktree. Git setup disables hooks, filters, text conversion, and fsmonitor execution.
Sanitization is a backstop, not a reason to place secrets in prompts or repository output. Do not include credentials in tasks, roles, schemas, notes, fixtures, or issues. Report a credential leak, sandbox escape, routing bypass, or cancellation defect through a private security advisory.
Support
| Platform | Status |
|---|---|
| macOS arm64 | Maintained and release-tested |
| Linux | Code paths exist; community-owned and unverified |
| macOS x64 | Unverified |
| Windows | Unsupported |
Linux support can graduate when it has a maintainer and CI evidence for process identity, descendant cancellation, settings discovery, sandbox behavior, filesystem isolation, and subscription-only routing.
Documentation
- Plugin reference
- Hydra 1.0 boundary
- Architecture decisions
- Hydra 1.0 verification report
- Contributing
- Security policy
- Changelog
Development
npm ci
npm test
npm run check
The default suite uses a mock Claude CLI and consumes no subscription allowance. Real Claude and isolation probes are opt-in and must stay disabled in public CI.
License
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。