Plugin

Installs into $CODEX_HOME or ~/.codex (or .codex with --project).

MCP

User config: ~/.codex/config.toml · Project: .codex/config.toml (trusted projects)
Optional per-tool approval modes are defined by Codex (auto · prompt · approve, …). In the TUI: /mcp.

Skill

With the plugin installed, prefer axguard-security so Codex calls axguard_security_review instead of inventing a scanner. Keep predictive risks separate from verified findings.