AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP verified MIT Self-run

Codex Context Reader

mcp-dangzitou-codex-context-reader · by dangzitou

A read-only MCP plugin for ChatGPT Chat that retrieves local project context on demand to reduce unnecessary token use.

— No reviews yet
0 installs
2 views
0.0% view→install

Install

$ agentstack add mcp-dangzitou-codex-context-reader

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • ✓ Prompt-injection patterns
  • ✓ Secret / credential exfiltration
  • ✓ Dangerous shell & filesystem operations
  • ✓ Untrusted network calls
  • ✓ Known-malicious package signatures

What it can access

  • ✓ Network access No
  • ✓ Filesystem access No
  • ✓ Shell / process execution No
  • ● Environment & secrets Used
  • ✓ Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/mcp-dangzitou-codex-context-reader)

Reliability & compatibility

✓ Security review passed
0 installs to date
— no reviews yet
● today

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Codex Context Reader? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Codex Context Reader

Use regular Chat on a Plus/Pro plan for read-only code analysis, leaving Codex usage for edits and tests. Codex Context Reader is a read-only Model Context Protocol server that connects ChatGPT web to a user-selected project through a private Tunnel.

It returns only a project overview, search matches, and bounded file excerpts. This reduces unrelated context and token use. Actual usage depends on the model and request.

> ChatGPT web requirement. In a desktop browser, check Plugins → Add → Create MCP app. If this option is available, you can create a private Tunnel connection. OpenAI also documents a Developer mode setting under Settings → Security and login; the visible entry point may differ by account and UI version. OpenAI Developer mode

[简体中文](README.zh-CN.md) · [Install](#install-and-chatgpt-web-setup) · [Security](#security) · [Contributing](CONTRIBUTING.md)

Install and ChatGPT web setup

Optional: ask a local coding assistant to prepare the connection

Paste this into a coding assistant on the computer that contains the project. It installs, tests, and prepares the private Tunnel. Account settings and the hidden key stay with you.

Set up https://github.com/dangzitou/codex-context-reader on this computer for read-only use in regular ChatGPT web through Secure MCP Tunnel. Make the smallest necessary changes.

1. Detect macOS, Linux, or Windows. Inspect the target before changing it. Clone or update the repository at ~/codex-context-reader on macOS/Linux, or %USERPROFILE%\codex-context-reader on Windows. Do not overwrite unrelated files.
2. Ensure Node.js 18+, Git, and ripgrep are available. Run npm test.
3. Tell me to open chatgpt.com in a desktop browser and check Plugins → Add → Create MCP app. If unavailable, check the documented Developer mode setting under Settings → Security and login. If neither entry is available, stop the ChatGPT-Tunnel setup.
4. Once I confirm MCP app creation is available: download tunnel-client only from the official OpenAI release or Platform Tunnel page, verify SHA-256 against the official checksum, and keep it in a user-owned local directory. Do not put it in this repository.
5. If I provide a tunnel_id, run npm run chat:tunnel -- --configure --tunnel-id . Otherwise tell me to create a Tunnel in Platform. Never create, request, print, store, or paste an API key into chat, files, Git, shell history, or logs.
6. Tell me the one remaining command to run in my own terminal: npm run chat:tunnel -- --prompt-key. Do not start the Tunnel unless I have entered the runtime key locally through that hidden prompt.
7. Once the client is ready, tell me to create an MCP app in ChatGPT Plugins: name it Project Context Reader, select Tunnel and its tunnel_id, choose No Authentication for this server, then create and connect it. Verify the green Connected state and test tool calls in a regular Chat using a nonsensitive sample project.

Do not expose the local project to the public internet. Do not modify any selected project.

What you must do yourself

| Step | Why it stays with you | | --- | --- | | Open chatgpt.com in a desktop browser and check Plugins → Add → Create MCP app | ChatGPT must offer custom MCP app creation. | | Create a Tunnel in Platform settings | It belongs to your OpenAI organization and ChatGPT workspace. | | Create a runtime API key and enter it in a local terminal | It is a credential; the launcher hides the input and does not save it. | | In ChatGPT Plugins, create the Tunnel connection | This changes your ChatGPT account settings. |

If Create MCP app is unavailable, check the documented Developer mode setting under Settings → Security and login. If neither entry appears, this ChatGPT web setup is unavailable for your account; restarting the Tunnel cannot add the missing feature.

Install and test the server

Requirements: Node.js 18+, Git, and ripgrep. Git context is optional. Install OpenAI's tunnel-client using the official Tunnel guide, verify its checksum, and put it on your PATH (or use --client with its absolute path in both launcher commands).

macOS/Linux:

git clone https://github.com/dangzitou/codex-context-reader.git "$HOME/codex-context-reader"
cd "$HOME/codex-context-reader"
npm test

Windows PowerShell:

git clone https://github.com/dangzitou/codex-context-reader.git "$env:USERPROFILE\codex-context-reader"
Set-Location "$env:USERPROFILE\codex-context-reader"
npm test

If the repository is already cloned, use its existing directory instead.

Start the private Tunnel

After the server is installed, MCP app creation is available, and you have a tunnel_id, configure the profile once:

cd "$HOME/codex-context-reader"
npm run chat:tunnel -- --configure --tunnel-id "your-tunnel-id"

Windows PowerShell:

Set-Location "$env:USERPROFILE\codex-context-reader"
npm run chat:tunnel -- --configure --tunnel-id "your-tunnel-id"

Start it whenever you use ChatGPT web:

npm run chat:tunnel -- --prompt-key

The key input is hidden and stays only in the launched process environment. doctor --explain runs before the Tunnel starts. Keep this terminal open and wait until it reports ready.

Add the connection in ChatGPT web

  1. At chatgpt.com, open Plugins → Add → Create MCP app.
  2. Set the name to Project Context Reader. Under Connection, choose Tunnel and select or paste your tunnel_id; the project-context-reader label should appear beneath it.
  3. Set Authentication to No Authentication: this local MCP server has no OAuth flow. The runtime API key authenticates tunnel-client separately. A description and icon are optional.
  4. Acknowledge the risk notice, choose Create, review the discovered tools, and connect the app. This confirmation dialog should appear:
  1. Confirm that the app page shows a green Connected status:
  1. Click Try in chat, add the app to a regular Chat if prompted, and test with a nonsensitive local repository:
Use Project Context Reader to read /Users/yourname/codex-context-reader. Call select_project, project_overview, search_code, and read_file, then summarize what you found with file paths. Do not modify files.

Replace yourname with your username (on Windows, use the full C:\Users\... path). Test only if this copy of the repository contains no private data. Check the Chat tool-call details for successful select_project, project_overview, search_code, and read_file results. A green Connected badge proves the connection, not that a project was read. The project ID expires after 30 minutes; select the project again when it does. Keep tunnel-client running while using Chat.

OpenAI documents Secure MCP Tunnel as an outbound connection for private MCP servers; it does not require an inbound public port. Tunnel guide

What it reads

| Tool | Purpose | | --- | --- | | select_project | Select an absolute local directory after user approval. Returns a random project ID. | | project_overview | Read root structure, branch, working-tree status, and recent commits. | | search_code | Search literal text in the selected project. | | read_file | Return up to 400 lines from a selected-project file. | | git_context | Read Git status, diff summary, and recent commits. |

Security

  • Reads stay within the chosen directory after resolving symlinks.
  • Project IDs are random, memory-only, and expire after 30 minutes or when the server stops.
  • read_file blocks .git, dependencies, output directories, .env*, certificates, and common key files. search_code currently does not exclude every certificate/key extension: use only nonsensitive repositories until this is fixed.
  • The server does not modify project files or run project code.
  • Tool results become ChatGPT context. Use only with repositories your organization permits you to share.
  • Secure MCP Tunnel is outbound-only. It does not open an inbound port or publish the project on the internet.

Development

npm test

The tests exercise MCP initialization, project selection, token-scoped reads, traversal rejection, and Tunnel-launcher argument generation.

License

[MIT](LICENSE) © Deng Zitao

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.