Skip to main content
Integrate Semgrep Guardian with Codex through Codex MCP.

Prerequisites

Setup

2
Update your ~/.codex/config.toml file and paste the following:
Codex does not expose a post-write hook, so Semgrep tools are surfaced through MCP and invoked when the agent calls them.

What rules does this setup use?

This integration scans with the rules enabled for your Semgrep organization through your Policies. See Rules and configuration for how this differs from the Claude Code remote plugin.

Next steps