Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/briandconnelly/codex-in-claudeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/briandconnelly/codex-in-claude/codex-in-claude)<a href="https://agentmods.dev/plugins/briandconnelly/codex-in-claude/codex-in-claude"><img src="https://agentmods.dev/badge/plugins/briandconnelly/codex-in-claude/codex-in-claude.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
codex-in-claude scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "codex-in-claude",
"version": "0.22.0",
"description": "Call OpenAI Codex from Claude Code for delegation, review, and second opinions.",
"author": {
"name": "Brian Connelly"
},
"homepage": "https://github.com/briandconnelly/codex-in-claude",
"repository": "https://github.com/briandconnelly/codex-in-claude",
"license": "MIT",
"keywords": [
"codex",
"claude-code",
"code-review",
"delegation",
"collaboration",
"mcp"
],
"skills": "./skills/",
"commands": "./commands/",
"mcpServers": "./.mcp.json",
"interface": {
"displayName": "Codex (for Claude Code)",
"shortDescription": "Delegate to Codex, review changes, and get second opinions.",
"longDescription": "codex-in-claude lets Claude Code call the OpenAI Codex CLI for an independent second opinion, structured code review, and delegated coding tasks. Delegation runs in an isolated git worktree and returns a reviewable diff that is never applied to your working tree. Read-only by default \u2014 which bounds what Codex writes, not what it can read.",
"developerName": "Brian Connelly",
"category": "Developer Tools",
"capabilities": ["MCP", "Skills"],
"websiteURL": "https://github.com/briandconnelly/codex-in-claude",
"defaultPrompt": [
"Get a second opinion from Codex on this approach.",
"Have Codex review my current changes.",
"Delegate this task to Codex and show me the proposed diff."
]
}
}
What it installs
The manifest is a name and a version. 8 skills, 1 MCP server travel with it, and installing the plugin installs all of them — 994 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill agent-bot-identity A 113 tokens
- Skill agent-friendly-github A 112 tokens
- Skill agent-friendly-mcp A 130 tokens
- Skill collaborating-with-codex A 141 tokens
- Skill separating-context-from-constraints A 157 tokens
- Skill agent-friendly-docs A 169 tokens
- Skill working-an-issue A 105 tokens
- Skill prek A 67 tokens
- MCP server codex-in-claude A not measured
What ships with it
1 file beside plugin.json in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago Changed f1d5af5c4b57
- 8d ago First seen · 37 lines scan A aaaae3408aa8
codex-in-claude is a plugin published in the GitHub repository briandconnelly/codex-in-claude (3 stars, last pushed 5d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
servicenow
ServiceNow developer data plane — incidents, CMDB, update sets, table explorer. 19 MCP tools + 4 guided skills, read-only mode, audit log.
apollo-mcp
FastMCP server exposing the full operational surface of the Apollo.io REST API. 27 tools covering sequences, campaign health, mailbox warmup, people/org enrichment, CRM contacts, tasks, labels, credit tracking, and programmatic template/sequence/mailbox-cap editing with audit logging.
slack-mcp
Multi-workspace Slack MCP server with draft+confirm safety, vault auto-export, and triple-mode auth (xoxc/xoxp/xoxb).
bootstrap-dpyc-operator
Bootstrap a new DPYC Tollbooth Operator MCP from an existing REST API, stdio MCP, or HTTP MCP. Wraps your domain logic in the canonical operator pattern — Lightning micropayments, Nostr identity, per-tool pricing — using tollbooth-sample as the live template.
gns3
Drive a GNS3 v3 network-emulation controller from Claude: build topologies, manage device lifecycle, snapshot, capture packets, manage templates/computes/RBAC, and automate device CLIs over node consoles.
google-workspace
Complete Gmail and Google Calendar integration via MCP.