MCP servers › io.github.AV-Labs-Co › cos-codex-bridge
MCP server · registry snapshot 2026-10-04
io.github.AV-Labs-Co/cos-codex-bridge
Operate Codex projects and tasks from a Chief of Staff with scoped access and durable receipts. — the publisher's description
Summary
io.github.AV-Labs-Co/cos-codex-bridge is a local MCP server listed in the official MCP registry at version 0.1.4. We have not tested it. It requires a setting the publisher marks as required (for example a URL part or a configuration value) that has no default, so we did not start it.
Key facts
- Runs
- local package
- Transport
- standard input/output
- Package
- npm · listed version current
- License
- MIT
- Dependencies
- 0 critical, 2 high advisories
- Repository
- public
- Topic
- productivity-and-docsAI-classified
- Last tested
- not tested
Worth knowing before you connect it
- 0 critical and 2 high advisories in its dependencies (as resolved on 2026-10-08).
Each line comes from a section below, with its source and date.
How fresh this is
- Live-tested
- no
- Last tested
- not tested
- Registry data
- snapshot 2026-10-04
- Package and repository
- checked 2026-10-06
Security testing
Has it been tested?
Feature #1It requires a setting the publisher marks as required (for example a URL part or a configuration value) that has no default, so we did not start it.
Required input the publisher declares: COS_BRIDGE_CONFIG.
What it is
Does the registry listing match what we found?
Feature #6The registry verifies a package once, when it is published, and does not re-check it. A difference below is about the listing, not a judgement of the publisher.
| Registry says | We found | Result | Source · date |
|---|---|---|---|
| Version 0.1.4 on npm | Exists and can be installed | matches | npm · 2026-10-06 |
| Repository github.com/AV-Labs-Co/cos-codex-bridge | Opens publicly | matches | api.github.com · 2026-10-06 |
Can it be installed, and is it up to date?
Version pin · advisories
Listed version
- Registry lists
- 0.1.4
- Latest stable
- 0.1.4
- Status
- current
- Withdrawn
- no
Source: registry.npmjs.org · 2026-10-06. About the version the registry lists; a manual install may resolve to a different one.
Dependency advisories
Counted in the full dependency tree as resolved on 2026-10-08 (npm audit). Bars share one scale. The package itself has no known vulnerability (OSV.dev).
Integrity, provenance, license
- Integrity
- sha512-keiFtT4XackxagFOh…
- Signature
- signed
- License
- MIT
Source: the package registry · 2026-10-06.
Usage
- Downloads
- 757 in the last month
Source: api.npmjs.org · 2026-10-06.
Who made it?
Feature #7 · lineage
Facts about the publisher. We do not turn them into a trust score.
- Namespace
- io.github.AV-Labs-Co
- GitHub owner
- an organization (AV-Labs-Co)
- Build record
- signed
- Repository
- github.com/AV-Labs-Co/cos-codex-bridge
- Stars
- 3
- Repository age
- 0–30 days
- Last push
- 0–30 days ago
- Archived
- no
Source: the registry entry and api.github.com · 2026-10-06.
Choosing
Common questions about io.github.AV-Labs-Co/cos-codex-bridge
Answered from the data aboveHas io.github.AV-Labs-Co/cos-codex-bridge been security tested?
Not yet. It requires a setting the publisher marks as required (for example a URL part or a configuration value) that has no default, so we did not start it.
Is the listed version current?
Yes. The registry lists 0.1.4, the latest stable release on npm.
Where is the source code of io.github.AV-Labs-Co/cos-codex-bridge?
In github.com/AV-Labs-Co/cos-codex-bridge, which opens publicly.
Reference
How is it classified?
18 fields
One value per field, each with its source. Fields written by AI models are marked. A field with no value says why.
“Not stated” means the source did not state it; “does not apply” means it does not apply to this kind of server; “our limit” means our own lookup failed.
Cite or correct this page
Sources and corrections
Suggested citation
ProtocolProbe. “io.github.AV-Labs-Co/cos-codex-bridge: MCP server record.” Data checked 2026-10-06. https://protocolprobe.com/mcp/servers/io.github.AV-Labs-Co/cos-codex-bridge
Figures are valid for the date shown. Our facts on this page are CC BY 4.0: reuse them with a link and the check date. Quoted text (the publisher’s descriptions, website quotes, tool names) is not ours to license.
As JSON: this record in the API · API documentation.
Something wrong, or is this yours?
If a fact here is wrong, tell us and we will re-check it. If you operate this server, you can authorize a full test.
Write to hello@protocolprobe.com · corrections log · methodology