Good Cop, Bad Cop: Unpacking openai/codex-plugin-cc

How an official OpenAI plugin turns Anthropic's terminal agent into an adversarial, multi-model workspace.

7 min read • View on GitHub • More from openai

Two vintage clockwork brains on a desk, one smooth glass and one brutalist brass, connected by a single telegraph wire. This represents the adversarial connection between Claude Code and OpenAI Codex.
The plugin enforces a strict communication channel between two competing architectures.

We love an open ecosystem and Codex should work with you wherever you are. Whether that's in our apps, in Xcode, JetBrains, OpenCode, Pi or even Claude Code.

Dominik Kundel, OpenAI Developer · implicator.ai
Key Takeaways

The Terminal Quality Gate

Imagine trying to exit your terminal, only to be blocked by an AI auditor. This is the visceral reality of the stop-review-gate-hook.mjs file. The plugin hooks directly into Claude Code's session lifecycle to intercept the exit command. It forces OpenAI's Codex to review the entire session's output before allowing the user to leave.

If Codex prepends a BLOCK: token to its assessment, the developer stays in the seat. This shifts the paradigm from AI as a pair programmer to AI as adversarial middle management. You are no longer just collaborating with an agent. You are answering to a second, competing model.

Dominik Kundel

Orchestrating the Rivalry

Running two powerful AI agents locally creates massive concurrency issues. The solution lives in app-server-broker.mjs. The Broker acts as a traffic controller for a persistent Codex background process.

The system utilizes a JSON-RPC multiplexer. It tracks active requests and streams, immediately returning a BROKER_BUSY_RPC_CODE (-32001) if Claude attempts to interrupt an ongoing Codex operation. It switches between Unix Sockets on macOS and Linux, and Named Pipes on Windows, ensuring robust Inter-Process Communication (IPC) across all environments.

The Broker Multiplexer handles concurrent requests to the Codex App Server, rejecting collisions to maintain stability.

The Rescue Protocol

Delegation is the next frontier of agentic workflows. The /codex:rescue command formalizes this. When Claude struggles with a specific bug, it can hand off the broken codebase to a specialized Codex subagent.

A close-up of a shattered magnifying glass over dense printed code, with metal forceps extracting a single flawed character. This represents the precision of the rescue subagent isolating a hyper-specific bug.
The rescue protocol acts as a surgical intervention when the primary model fails to resolve an issue.

State management within lib/state.mjs ensures these jobs persist. The background task runs quietly while the user continues working in Claude. The developer can check progress with /codex:status or pull the solution with /codex:result.

The Adversarial Advantage

Why run two models at all? The answer lies in the /codex:adversarial-review command. Standard AI code reviews hunt for syntax errors. The adversarial review is prompted specifically to attack design choices, hidden assumptions, and architectural tradeoffs.

No single model is perfect. By pitting Claude's long-context reasoning against Codex's implementation scrutiny, developers achieve a level of rigor previously reserved for senior engineering teams.

FeatureSingle-Agent WorkflowAdversarial Workflow (with Plugin)
Primary FunctionGeneration and ChatGeneration paired with strict Critique
Error CatchingSelf-correction promptingCross-model auditing
IPC OverheadNone (Single Process)Managed via Unix Sockets / Named Pipes
Quality GateVoluntary manual reviewHard terminal exit block
/plugin marketplace add openai/codex-plugin-cc
/plugin install codex@openai-codex
/codex:setup