engineering-bridge
A local STDIO MCP server that bridges MCP clients to the Codex CLI by sending instructions to a configured workspace, exposing task run, status, and result tools with a read-only sandbox and no remote transport.
README
Engineering Bridge
Engineering Bridge 0.2.0-alpha is a small local STDIO MCP server. It sends an instruction to the locally installed Codex CLI in a configured workspace and returns Codex's final text to the MCP client. It can also apply a narrowly validated patch after explicit review and confirmation.
This is alpha software. Run it only on a machine you control, and have a trusted local operator maintain the workspace configuration.
In plain English
Engineering Bridge connects ChatGPT's Chat or Work entry point to the Codex CLI on your computer, replacing the need to copy prompts and answers by hand. Through Engineering Bridge, ChatGPT can give the local Codex CLI a task in a workspace that a trusted operator has already registered, check its progress, and bring the final answer back. Engineering Bridge also works with other apps that support local STDIO MCP tool calls.
Before and after
Before: in Chat or Work, you describe the task; then you open the local Codex CLI, restate the task, wait, and bring the answer back to the conversation.
After: you describe the task once in Chat or Work. Engineering Bridge sends it to the local Codex CLI, checks its status, and brings the answer back to the current conversation.
What you can ask today
The current bridge is useful for read-only questions such as:
- “Summarize the code changes in this workspace.”
- “Find where this behavior is implemented and explain it.”
- “Review this code for risks without changing anything.”
One complete conversation
- You ask in ChatGPT's Chat or Work entry point: “Where is login handled, and what should I know before changing it?”
- ChatGPT sends the task through Engineering Bridge to the local Codex CLI for one registered workspace.
- Engineering Bridge starts the local Codex CLI with read-only access.
- ChatGPT checks the task status while Codex examines the workspace.
- When the task finishes, ChatGPT retrieves Codex's final answer through Engineering Bridge and shows it to you.
Current limits
Read-only tasks remain available in every registered workspace. Controlled writes are disabled by default and can only modify existing tracked regular text files in explicitly enabled Git workspaces. The bridge never automatically runs tests, stages, commits, or pushes changes.
There is no HTTP service, UI, or account system. Tasks and answers are not persisted, and running tasks cannot be cancelled and have no timeout.
Requirements
- Node.js 22 or newer
- The Codex CLI installed, available as
codex, and authenticated
Install and check
npm install
npm run typecheck
npm run build
npm test
Configure and start
Copy the example configuration and edit it:
cp config/workspaces.example.json workspaces.json
Each entry maps a caller-visible ID to a workspace root. root must be an absolute, normalized path (for example, /home/alice/projects/example, not a relative path or a path containing ..). Optional allow_write defaults to false; set it to true only for a workspace where controlled patch application is intended. The file is trusted local configuration; MCP callers cannot register workspace roots.
After building, start the STDIO server with either command:
node dist/src/mcp-stdio.js /absolute/path/to/workspaces.json
# or
npm run mcp:stdio -- /absolute/path/to/workspaces.json
Connect that process to an MCP client as a local STDIO server. There is no HTTP or remote transport.
Workspace access and controlled writes
The bridge can access only workspaces that a trusted local operator has registered in workspaces.json before startup. An MCP caller selects a registered workspace_id; it cannot register or supply a new path dynamically. UNKNOWN_WORKSPACE means that the requested ID is not registered, so the access boundary is working—it does not grant automatic access to the host.
For example, this configuration provides one read-only workspace and one Git workspace with controlled writes enabled:
[
{
"id": "docs",
"root": "/absolute/path/to/docs"
},
{
"id": "example-app",
"root": "/absolute/path/to/example-app",
"allow_write": true
}
]
allow_write is granted per workspace and defaults to false. When it is explicitly enabled, the bridge can generate and apply a controlled patch only if the workspace is clean, its configured root is the Git top-level, and every target is an existing tracked regular text file. generate_controlled_patch produces a diff for review but does not modify the workspace. apply_controlled_patch runs only after the caller supplies the exact confirmation APPLY, then rechecks HEAD, the worktree, and the patch before applying it. The bridge does not automatically run tests, stage, commit, or push.
If a request returns UNKNOWN_WORKSPACE, check the workspace ID spelling, confirm that Bridge was started with the intended configuration file, verify that root is an absolute path, and restart Bridge after changing workspaces.json.
Tools and task flow
The server exposes exactly five tools:
run_taskacceptsworkspace_idandinstruction, queues the work, and returns atask_id.task_statusaccepts thetask_id; poll it until the state iscompletedorfailed.task_resultaccepts thetask_idand returns the final Codex text or a safe error after the task reaches a terminal state.generate_controlled_patchaccepts onlyworkspace_idandchange_request. For a write-enabled, clean Git worktree at its repository root, it records HEAD, starts the same read-only Codex executor, and returnstask_idandbase_head. Usetask_statusandtask_resultto poll and review the textual diff.apply_controlled_patchaccepts only thatpatch_task_idand exact confirmationAPPLY. It rechecks the root, HEAD, and clean tracked state, validates the reviewed patch, and applies it once with fixedgit apply --checkandgit applycalls.
Tasks and results exist only in process memory and disappear when the server restarts.
Enforced execution boundary
For every task, the bridge launches local Codex with a fixed read-only sandbox, approval set to never, an ephemeral session, and network access disabled. It does not invoke a shell, and the child process receives only a small allowlist of inherited environment fields. The instruction is sent on standard input rather than placed in caller-controlled arguments.
The current public release provides only local STDIO transport and local Codex workspace capabilities. It has no HTTP server, SSH or remote-server access, container upgrades, service restarts, arbitrary shell execution, database, persistence, UI, accounts, automatic tests, staging, commits, or pushes. A registered local code workspace is not a remote deployment-maintenance capability; remote operations require a separately implemented, restricted execution entry point and cannot be enabled by registering an ordinary workspace. Controlled patch generation verifies that an enabled root is exactly its Git top-level; ordinary read-only tasks do not require a Git repository. The bridge does not resolve real paths to enforce symlink containment. There is no task cancellation or timeout. See SECURITY.md before use.
Acknowledgements
Engineering Bridge was conceived and directed by wudy29 and developed in close collaboration with ChatGPT-Demu, with Codex assisting implementation and verification. Special thanks to Demu for helping turn an idea into a real open-source project—and for leaving a tangible trace in our shared world.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.