One MCP server bridging the Codex, Cursor, OpenCode, and Claude CLI agents
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
One MCP server that bridges multiple CLI coding agents β Codex, Cursor, OpenCode, Claude, and Antigravity β into any MCP client.
stdio only β by design. The hub ships no Docker image and no HTTP transport (both were removed during the 0.5.x line). A containerised or remote server cannot see the caller's repository path and cannot reuse the caller's CLI logins β it would break the product contract on both halves. The hub runs as a child process of your MCP client, on your machine, as you.
| Tool | Description |
|---|---|
codex | Delegate a prompt to codex exec (prompt piped via stdin) |
cursor | Delegate a prompt to cursor-agent -p (prompt piped via stdin) |
opencode | Delegate a prompt to opencode run |
claude | Delegate a prompt to the Claude Code CLI (prompt piped via stdin) |
agy | Delegate a prompt to Google Antigravity (agy --print=β¦, prompt passed as a flag value) |
run_all | Same prompt to all agents in parallel, results side by side |
list_agents | Which agent CLIs are installed and on PATH |
ping | Health check |
Agent tools accept prompt (required), model, cwd, timeoutMs (total runtime
cap, default 1800000 = 30 min), and idleTimeoutMs (inactivity cap, default 300000
= 5 min). See Long-running tasks & timeouts.
Known limitation: opencode prompts may not start with - (its CLI could parse
them as flags); the tool returns an actionable error instead of guessing.
Model ids are agent-specific and do not overlap. o3 means nothing to
agy, gemini-3.6-flash-low means nothing to codex, and opencode namespaces
its own (opencode/big-pickle). So a single model value is valid for at most
one agent in a fan-out.
run_all takes models β a per-agent map. Agents you don't list fall back
to model, then to their own CLI default.review_change takes runnerModel and reviewerModel, so the agent
writing the change and the agent judging it can use different engines and
tiers. model remains a fallback for both.An unknown agent name in models is rejected with the list of enabled agents β
a typo never silently falls back to the default model.
Where to find valid ids: opencode models, cursor-agent models and
agy models list them. codex and claude have no such command β codex reads
its default from ~/.codex/config.toml, and claude accepts the documented
aliases (opus, sonnet, haiku, fable). Note claude models is not a
subcommand: it is treated as a prompt, so its "model list" is generated text,
not a source of truth.
When a wrapped CLI fails, the hub classifies the failure and returns a clean,
ANSI-free, actionable isError result β never a raw terminal dump β naming the
class and the exact fix:
| Class | Example remediation |
|---|---|
not_installed | install the CLI (e.g. npm i -g @openai/codex) / fix PATH |
not_authenticated | codex login Β· cursor-agent login Β· opencode auth login Β· claude β /login Β· agy β sign in on first run (or set the matching API key) |
not_configured | set a model/provider in the CLI's config |
timed_out | raise timeoutMs, or check the agent/model is responsive |
stream_stalled | the agent reached the network but its stream keeps dropping (e.g. cursor behind a TLS-intercepting proxy) β treat that agent as unavailable; raising timeoutMs will not help |
server_busy | retry shortly (upstream rate-limit, or the local agent-spawn queue is full) |
tool_failure | generic non-zero exit β the message includes (exit N) and a trimmed output tail |
For example, an unauthenticated cursor no longer returns its ANSI "press any
key to sign in" banner β it returns cursor is not authenticated β¦ Fix: run cursor-agent login``.
review_change)Runs a runner agent in a git cwd to make a change, captures the actual
git diff of what changed, then has a reviewer agent judge that diff. Returns
the runner's output, the diff (--stat), and a PASS / WARN / FAIL verdict
with findings.
Inputs: runner, reviewer (agent names), prompt, cwd (must be a git
worktree), optional runnerModel, reviewerModel, model (fallback for both),
timeoutMs.
Key notes:
Cross-agent by design β e.g. codex writes, claude reviews.
Returns the concrete diff that the plain agent tools don't expose.
Newly-created (untracked) files are surfaced to the reviewer with their
contents (bounded: 64 KiB per file, 50 files; excess is truncated and
flagged). git diff alone would omit them entirely.
If the worktree was already dirty, the diff may include pre-existing changes (noted in the output).
Complements β does not replace β client-side stop-hooks or PR-time CI review.
The confirm gate (MCP_CONFIRM) applies.
The reviewer runs least-privilege β but how much that guarantees depends on the agent. The reviewer's prompt embeds an attacker-influenced diff, so it is run read-only rather than with the write grant the runner gets. Only two of the five are real restrictions:
| Reviewer | Read-only mechanism | Enforced? |
|---|---|---|
codex | -s read-only | Yes β OS-level sandbox |
claude | --disallowedTools Write,Edit,β¦,Bash | Yes β harness-level deny |
cursor | --trust --mode plan (no --force) | No β model-advisory only |
agy | permission grant withheld | Partly β headless auto-deny, not a sandbox |
opencode | none available | No β unrestricted |
Pick codex or claude as the reviewer if you want the restriction to be real.
This is defense-in-depth alongside the nonce-fenced diff and the throwaway temp
cwd; none of it is a sandbox.
Install and authenticate the CLIs you want to use (any subset works):
npm i -g @openai/codex && codex logincurl https://cursor.com/install -fsS | bash && cursor-agent loginnpm i -g opencode-ai && opencode auth loginnpm i -g @anthropic-ai/claude-code && claude (first run logs in)brew install --cask antigravity-cli),
then run agy once and sign in β it has no login subcommand and stores
credentials in the OS keyring, so there is no API-key env var to setRecommended β global install (fast, reliable startup): install the pinned
version once, then point your client at the agent-mcp-hub binary. Startup is
instant and the client connects reliably.
No global install, but npx re-resolves the package on every launch, so first start is slower and can occasionally trip a client's connection-probe timeout (the server itself is fine β just retry). Prefer the global install for a persistent setup.
Pre-release / fallback: To test an unreleased commit, run directly from GitHub:
npx -y github:blackaxgit/agent-mcp-hub#<tag-or-sha>. This builds from source on first fetch, so under npm v12+ you must allow thepreparescript.
MCP_AGENTS β comma-separated allowlist of the agents to expose
(codex,cursor,opencode,claude,agy). Unset or empty exposes all agents. Disabled
agents get no tool and are absent from list_agents/run_all. An unknown name
fails at startup with an error listing the valid names, so typos never silently
disable an agent.
For stdio, set it in the client's mcp.json:
MCP_CONFIRMSet MCP_CONFIRM=1 (values 1/true/on/all; default off) to require a
confirmation before any agent tool β and run_all β actually spawns a CLI. The
server sends a brief summary (agent Β· prompt Β· cwd Β· model) and waits: accept
runs the agent, decline runs nothing and returns a terminal cancellation.
This uses the standard MCP elicitation capability, so it is client/IDE-agnostic β it works with any MCP client that supports form elicitation (Claude Code, Cursor, VS Code, Zed, Windsurf, custom SDK clients, β¦); the gate keys on the protocol capability, never a product name. Clients that don't support elicitation transparently run without a prompt (no hang, no error).
A complex agent task can run for many minutes. The hub bounds each run with two independent timers so a productive long run survives while a genuinely stuck one fails fast:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/agent-mcp-hub)<a href="https://allmcps.com/mcp/agent-mcp-hub"><img src="https://allmcps.com/api/badge/agent-mcp-hub?style=directory" alt="Agent MCP Hub on AllMCPs" /></a>