Plugin
$CODEX_HOME or ~/.codex (or .codex with --project).
MCP
~/.codex/config.toml · Project: .codex/config.toml (trusted projects)
auto · prompt · approve, …). In the TUI: /mcp.
Skill
With the plugin installed, preferaxguard-security so Codex calls axguard_security_review instead of inventing a scanner. Keep predictive risks separate from verified findings.