Codex Protocol Guardian
БесплатноНе проверенValidates governance evidence for Codex development tasks, enforcing requirements alignment, single-active-subject candidates, executable specifications, and in
Описание
Validates governance evidence for Codex development tasks, enforcing requirements alignment, single-active-subject candidates, executable specifications, and independent gates for traceable review packets.
README
MCP governance package for keeping Codex development tasks aligned to a requirements package, one active candidate subject, an executable specification, independent gates, and a traceable review packet.
This package does not spawn child agents, export role prompts, execute tasks, or write runtime state. It validates governance evidence and can append immutable finding archives; it never approves its own work. Legacy role, dispatch, and sub-agent modules are not included in the package surface.
Structure
<checkout-root>
|-- pyproject.toml
|-- README.md
|-- src\agent_team_mcp
| |-- server.py
| |-- tools.py
| |-- protocol_guardian.py
| `-- data
| |-- protocol_guardian.json
| `-- protocols
| |-- protocol-driven-development.md
| |-- module-interface-boundary.md
| |-- code-size-governance.md
| |-- acceptance-alignment.md
| `-- traceability-checkpoint.md
`-- tests
The MCP server advertises itself as codex-protocol-guardian.
Surface Boundary
The governance package has no required or discoverable skill surface. Legacy role, prompt, dispatch, and sub-agent modules were removed from the package. Frontend, external-tool, and webnovel material is optional domain content and is not loaded into the default governance context. New code must use the public governance functions listed below.
The source tree may retain historical skill documents for reference, but the package build and resource loader include only governance protocols and the executable specification template. Legacy skill, role, and prompt data is not a loadable package resource.
Tools
list_protocols: returns the protocol manifest, required artifacts, workflow phases, hard gates, and public tool list.export_protocol_context: returns the full protocol context, loaded protocol bodies, hashes, required artifacts, workflow, hard gates, and instructions.export_execution_plan_template: returns starter templates for the required.codex/protocol/*artifacts, including the executable Spec template and the module-boundary and communication-capacity declaration required before file design.audit_alignment_packet: checks whether a final packet has requirements, plan, acceptance protocol, traceability, changed files, validation evidence, an independent review signal, candidate authority, decomposition, solution design, scope, and convergence gate evidence. Missing governance evidence is blocked; there is no legacy bypass.validate_candidate_manifest: validates the single-active-subject manifest.transition_candidate: applies one legal lifecycle event without mutation.classify_review_finding: decides whether a finding stays in the candidate or requires a successor.validate_requirements_decomposition: validates frozen atomic requirements before design starts.validate_solution_design: validates alternatives, exact requirement binding, module boundaries, and scope digest.validate_change_scope: rejects changed files outside the design allow-list.validate_finding_ledger: validates finding fingerprints, closure evidence, successor inheritance, and recurrence blocking.validate_finding_archive: validates the persisted finding archive and parent candidate chain.read_finding_archive: loads and verifies a relative archive path under the configured governance archive root.append_finding_archive: atomically appends a governance record with an expected-digest conflict check; absolute paths and..traversal are rejected.
Required Artifacts
Codex should keep these files in the target project during a development task:
.codex/protocol/current/requirements.md
.codex/protocol/current/specification.md
.codex/protocol/current/execution_plan.md
.codex/protocol/current/acceptance_protocol.md
.codex/protocol/current/traceability.md
.codex/protocol/current/decision_log.md
The package does not write runtime state. Its only write operation is the
explicit append_finding_archive governance-artifact operation, which uses an
expected digest and atomic replacement to prevent lost updates. The archive
root is configured by AGENT_TEAM_MCP_ARCHIVE_ROOT, or defaults to
.codex/protocol/current/archives under the current project.
Local Runtime Check
Install this checkout into the project environment before starting MCP:
python -m pip install --editable .
python scripts/verify_runtime_source.py
python -m pip install --requirement requirements-lock.txt
After reinstalling the package, restart or re-register the MCP process so its manifest and protocol resources come from this checkout.
Workflow
- Load
export_protocol_contextbefore editing. - Create or refresh the required protocol artifacts.
- Assign stable requirement ids (
R1,R2, ...) and acceptance ids (A1,A2, ...). - Freeze a requirements decomposition before writing a solution design. Each item needs an observable result, boundaries, non-goals, dependencies, and an acceptance id.
- Validate a solution design against the frozen decomposition. The design must choose among alternatives and declare public interfaces, responsibilities, forbidden duties, allowed files, and a scope digest.
- Build
specification.mdfrom the packaged executable Spec standard. Execute every rule against its production input projection before planning code. - Keep one active candidate subject. Archive rejected and superseded subjects,
linked with
replacesandsuperseded_by. - A material requirement, design, or scope finding creates a successor; minor findings may be fixed in the current candidate.
- Every governed packet must carry a finding ledger. Repeated fingerprints inherited from a successor chain block acceptance until root-cause evidence exists.
- Report independent gates for scope drift, review independence, CI completeness, traceability closure, artifact provenance, and runtime acceptance boundary. CI completeness also requires external platform evidence for branch protection, required checks, CODEOWNER approval, stale-review dismissal, and merge-queue policy.
- Record process metrics separately: time in state, review iterations, superseded count, rejection rate, open blockers, lead time, change-fail rate, and recovery time.
- Before each edit, declare the phase, requirement ids, acceptance ids, allowed files, and expected evidence.
- Before choosing files for a feature component, declare its single public interface, internal responsibility split, dependency direction, expected traffic, ordering/idempotency, backpressure, failure handling, scaling, and observability. A single public interface must not serialize all work.
- Split internal files by responsibility and change reason. Do not use fixed line-count thresholds or put facade, business logic, storage, and external communication in one file. Single-responsibility leaf files remain valid.
- After each edit, compare the diff against requirements, the specification, the execution plan, acceptance protocol, traceability, and non-goals.
- Record plan deviations in
decision_log.md. - Run validation and export a review packet.
- Treat self-test as evidence only. Final acceptance requires independent review, CI, or explicit user approval.
Codex MCP Config
Use the checkout's environment explicitly so MCP cannot resolve a sibling editable install with the same distribution name:
[mcp_servers.protocol_guardian]
command = "<checkout-root>/.venv/Scripts/python.exe"
args = ["-m", "agent_team_mcp.server"]
Verify
cd <checkout-root>
python -m pytest -q
python -m ruff check .
python scripts/verify_runtime_source.py
The test suite inserts this checkout's src directory before site-packages so
an unrelated editable install with the same distribution name cannot produce a
false green result.
Установить Codex Protocol Guardian в Claude Desktop, Claude Code, Cursor
unyly install codex-protocol-guardianСтавит в Claude Desktop, Claude Code, Cursor и VS Code — сам разбирается с npx, uvx и сборкой из исходников.
Впервые? Поставь CLI: curl -fsSL https://unyly.org/install | sh
Или настроить вручную
Выполни в терминале:
claude mcp add codex-protocol-guardian -- uvx --from git+https://github.com/wewq36720-cyber/agent-mcp-codex agent-team-mcp-stableПошаговые гайды: как установить Codex Protocol Guardian
FAQ
Codex Protocol Guardian MCP бесплатный?
Да, Codex Protocol Guardian MCP бесплатный — установка в пару кликов через Unyly без оплаты.
Нужен ли API-ключ для Codex Protocol Guardian?
Нет, Codex Protocol Guardian работает без API-ключей и переменных окружения.
Codex Protocol Guardian — hosted или self-hosted?
Self-hosted: сервер запускается локально на твоей машине командой из раздела установки.
Как установить Codex Protocol Guardian в Claude Desktop, Claude Code или Cursor?
Открой Codex Protocol Guardian на unyly.org, выбери вкладку своего клиента (Claude Desktop, Claude Code, Cursor) и нажми Install — конфиг сгенерируется автоматически, без правки JSON.
Похожие MCP
GitHub
PRs, issues, code search, CI status
автор: GitHubFilesystem
Secure file operations with configurable access controls.
Memory
Knowledge graph-based persistent memory system.
Template MCP Server
A CLI tool to create a new Model Context Protocol server project with TypeScript support, dual transport options, and an extensible structure
автор: mcpdotdirectAmap Maps Mcp Server
MCP server for using the AMap Maps API
автор: duxiaohuiSupabase
Database, auth and storage
автор: SupabaseEverything
Reference / test server with prompts, resources, and tools.
Git
Tools to read, search, and manipulate Git repositories.
Sequential Thinking
Dynamic and reflective problem-solving through thought sequences.
Time
Time and timezone conversion capabilities.
Compare Codex Protocol Guardian with
Не уверен что выбрать?
Найди свой стек за 60 секунд
Автор?
Embed-бейдж для README
Похожее
Все в категории development
