SuperAgent MCP server for orchestrating Codex agent calls with concurrency
SuperAgent exposes 4 tools with STDIO transport only, limiting remote accessibility. Tool naming lacks action verbs (codex, gemini, continue, list-agents are acceptable but generic). Descriptions are present and reasonably detailed (100-200 chars), which is above baseline. However, schema quality is inconsistent: schemas ARE defined via Zod but parameter descriptions are sparse or missing for critical fields. All tools accept dynamic agent names but provide no enum constraints or validation examples. The codex, gemini, and continue tools share identical or nearly-identical schemas with copy-pasted descriptions, signaling a composition problem, these should either be consolidated or differentiated. Error handling is present (status='ok'|'failed') but does not guide recovery ('User not found, try search_users()' style guidance is absent). Security concerns: the 'extraArgs' parameter accepts arbitrary CLI arguments, creating potential command injection vectors. No evidence of rate limiting, permission gating, or audit logging. Output is formatted as plain text with ANSI colors rather than structured JSON, forcing LLMs to parse unstructured responses. Schema definitions use zod-to-json-schema conversion (correct approach) but descriptions are embedded in schema generation, making them harder to audit.
Run Codex CLI agent with parallel execution. Supports multiple tasks concurrently. Use 'workingDirectory' to access different project folders. Codex has full system access. Use 'agent' parameter to invoke a specific agent (run 'list-agents' to see available agents).
Run Continue CLI agent with parallel execution. Supports multiple tasks concurrently. Use 'workingDirectory' to access different project folders. Requires CONTINUE_CONFIG_PATH environment variable to be set. Use 'agent' parameter to invoke a specific agent (run 'list-agents' to see available agents).
Run Gemini CLI agent with parallel execution. Supports multiple tasks concurrently. Use 'workingDirectory' to access different project folders. Auto-approves all actions (YOLO mode). Use 'agent' parameter to invoke a specific agent (run 'list-agents' to see available agents).
List all available specialized agents for use with codex, gemini, and continue tools
Command injection risk in 'extraArgs' parameter. Tool accepts arbitrary CLI arguments without sanitization, allowing LLMs to pass malicious payloads to subprocess execution.
Three near-identical tools (codex, gemini, continue) with copy-pasted schemas and descriptions. This violates single-responsibility principle and wastes reasoning cycles for LLM tool selection.
Parameter descriptions incomplete or missing. 'agent', 'extraArgs', 'timeoutMs', 'workingDirectory' lack meaningful descriptions. 'prompt' is vague, no guidance on expected format or length.
No enum constraints on 'agent' parameter. Tool description says 'run list-agents to see available agents' but does not enumerate valid values or provide type constraints.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 38 | - | v1 |
Unstructured text output with ANSI color codes. Tool returns plain text rather than structured JSON, forcing LLMs to parse and extract results, increasing error rates and token waste.
No error recovery guidance. Errors report 'status: failed' with raw error text. No suggestions for retry, alternative tools, or user action.
No pagination or result limiting. Tools accept concurrency parameter but no per-result limit or pagination for outputs. Large responses could exhaust context window.
Missing timeout validation. 'timeoutMs' accepts arbitrary numbers with stated range 'default: 30 min, max: 60 min' but no numeric min/max constraints in schema. LLM could pass negative or zero values.
No permission gating or audit trail. Tools grant full system/agent access. No logging of who called what, with which parameters, or what the outcome was.
STDIO transport limits remote accessibility. Server cannot be invoked by hosted MCP clients or remote agents. No SSE or HTTP variant available.