Claude Code × Antigravity + Codex + Copilot + Cursor — MCP Bridge
Drive four external coding CLIs — Google's Antigravity (Gemini 3.5 Flash), OpenAI Codex, the GitHub Copilot CLI, and Cursor — as sub-agents inside Claude Code. Text answers, image generation, real repo work, and parallel swarms, on quota you already pay for.
One MCP server, four backends. It exposes Google Antigravity, OpenAI Codex, the GitHub Copilot CLI, and Cursor to Claude Code as clean MCP tools so you can delegate work to a different model family mid-task — without leaving your terminal, and on the subscriptions you already have. Each backend is independent: install one, two, three, or all four.
- 🛰️ Antigravity (
agy, Gemini 3.5 Flash High). Fast, cheap tool-calling — and the only backend with an image model. Its headless print mode (agy -p) historically had a stdout bug: it wrote the answer to the controlling terminal instead of its stdout, so anything capturing stdout got nothing (and, under a TUI, agy's text leaked into the host's prompt). agy 1.0.15 fixed this on Windows —-pnow writes the clean answer to stdout — so the bridge prefers stdout and falls back to reading agy's own transcript files only when stdout is empty (older agy, non-Windows, or--sandboxruns). It still detaches agy from the terminal so older versions can't leak. - 🤖 Codex (
codex exec, OpenAI). A strong reasoner for real code/repo work. It writes its final message straight to a file the bridge asks for (no scraping), supports model selection, and has a real, enforced sandbox. - 🐙 Copilot (
copilot -p, GitHub). GitHub's agentic coder. Stdout-native like Codex (-sprints just the answer), with model selection (--model), a best-effort tool/path permission knob, and a deterministic resume mechanism (the bridge sets each session's UUID itself). - ✳️ Cursor (
cursor-agent -p, Cursor). Cursor's agentic coder, with the widest model menu — GPT, Claude, Grok, and Composer via--model(validated againstcursor-agent models). Stdout-native like Codex/Copilot (--output-format textprints just the answer), an agent-enforced sandbox (read-only via--mode ask), and a deterministic resume mechanism (the bridge mints each chat's id itself viacreate-chat). No image model.
All four share the same niceties: a *_continue to resume a thread, a live "watch" window
to see the agent work, a unified agent_swarm that runs many tasks in parallel across
all backends at once, and *_status diagnostics that spend no quota.
[!WARNING] This runs unsandboxed code with your privileges.
agy -pauto-executes its tools (read/write files, run shell commands, reach the network) with no usable approval gate — its--sandboxblocks only shell commands, leaving file writes and network egress wide open.codex execalso runs autonomously, but itssandboxflag (defaultread-only) is a real, enforced boundary.copilot -pruns headless with--allow-all-tools; itssandboxmaps to best-effort tool/path permissions (read-only denies the local write/shell tools) — safer than agy, but not an OS sandbox like Codex's.cursor-agent -pruns headless with--trust(and--forcefor writes); itssandboxis agent-enforced (read-only =--mode ask, which makes the write/shell tools unavailable) — best-effort like Copilot, not an OS sandbox. In all four cases theworkspaceargument is a starting context, not a security boundary. Only use these with trusted prompts on trusted content; for real isolation, run the bridge inside a container or VM. Full details →
Why you'd want this
| 🧠 Second opinion | Ask a different model family — Gemini or GPT — mid-task without switching tools. |
| 🎨 Image generation | Have Gemini draw an image and get the saved file back — no extra API key or image tool. |
| 🛠️ Real coding sub-agent | Hand a focused repo task to Codex with a real workspace-write sandbox. |
| 💸 Cheap delegation | Burn Antigravity / Codex quota on grunt work instead of Claude tokens. |
| 🐝 Parallel fan-out | Run N tasks at once, mixing Gemini and Codex workers in a single swarm. |
| 📁 Cross-repo reads | Point a worker at another project directory and let it read/answer there. |
| 🔌 Zero new auth | Piggybacks the logins you already did — no keys for the bridge to manage. |
The four backends at a glance
The bridge normalizes all four CLIs into the same shape, but they differ where it matters. Pick per task:
🛰️ Antigravity (agy) |
🤖 Codex (codex exec) |
🐙 Copilot (copilot -p) |
✳️ Cursor (cursor-agent -p) |
|
|---|---|---|---|---|
| Model | Selectable via model (agy's --model); Gemini 3.5 Flash (High) default (see Model & auth) |
Selectable via model (codex's -m) |
Selectable via model (--model) |
Selectable via model (--model), validated against cursor-agent models |
| Best at | Fast, cheap tool-calling; quick answers | Heavier reasoning; real code/repo work | Agentic coding; real code/repo work | Agentic coding; wide model menu (GPT/Claude/Grok/Composer) |
| Image generation | ✅ antigravity_image (+ antigravity_image_swarm) |
❌ no image model | ❌ no image model | ❌ no image model |
| Sandbox | ❌ no real boundary (--sandbox blocks only shell) |
✅ real, enforced: read-only / workspace-write / danger-full-access |
⚠️ best-effort: tool/path permissions (read-only denies write/shell) — not an OS sandbox |
⚠️ agent-enforced: mode/force (read-only = --mode ask, write/shell tools unavailable) — not an OS sandbox |
| How the answer is read | stdout on agy 1.0.15+ (Windows); else scraped from transcript.jsonl |
Written to a file via -o/--output-last-message |
stdout (-s silent mode) |
stdout (--output-format text) |
| Continue mechanism | Pins the workspace's conversation id (--conversation) |
Resumes the session id (codex exec resume <id>) |
Resumes a self-set session UUID (--session-id) |
Mints a chat id (create-chat) and resumes it (--resume <id>) |
| Auth | OS credential store (AI Pro session) | codex login (ChatGPT account or API key) |
OS credential store (copilot login) or a GitHub token env |
cursor-agent login (OS credential store) or CURSOR_API_KEY |
| In a swarm | Runs with an isolated HOME to avoid state races |
Fresh one-shot — needs no isolation | Fresh one-shot — needs no isolation | Fresh one-shot — needs no isolation |
How it works
All four backends run headless and one-shot per call; the bridge's job is to get a clean answer out of each and hand it to Claude Code as a plain string.
flowchart LR
A([Claude Code]) -- "MCP tool call" --> B["bridge<br/>(server.py)"]
B -- "antigravity_*" --> C[agy -p]
B -- "codex_*" --> D[codex exec]
B -- "copilot_*" --> E[copilot -p]
B -- "cursor_*" --> F[cursor-agent -p]
C -- "stdout (1.0.15+)<br/>or transcript.jsonl / .db" --> B
D -- "output-last-message file" --> B
E -- "stdout (-s silent)" --> B
F -- "stdout (--output-format text)" --> B
B -- "plain text" --> A
Antigravity. On agy 1.0.15+ (Windows), agy -p writes its clean final answer straight to
stdout, and the bridge returns that directly. On older agy — or non-Windows, or a --sandbox run —
stdout stays empty and the bridge falls back to agy's own transcript at:
~/.gemini/antigravity-cli/brain/<conv-id>/.system_generated/logs/transcript.jsonl
For the fallback it locates the conversation via cache/last_conversations.json (falling back to the
newest brain/ directory touched since launch), streams the transcript, and returns the final
source=MODEL, status=DONE, type=PLANNER_RESPONSE entry — the answer, minus the intermediate
tool-calling steps (or the SQLite .db agy dual-writes, when no JSONL exists). Either way,
antigravity_continue pins the workspace's exact conversation id via --conversation, so it
never resumes the wrong thread.
Codex. codex exec is well-behaved: the bridge passes -o/--output-last-message <file> and
codex writes its final message straight there — no scraping. Continue works by capturing the session
id from codex's own rollout files (~/.codex/sessions/.../rollout-*.jsonl) and resuming with
codex exec resume <id>, falling back to the newest on-disk session for that cwd after a server
restart.
Copilot. copilot -p "<prompt>" -s runs a prompt non-interactively and prints the clean final
answer to stdout — the bridge reads it there, no scraping. It runs headless with --allow-all-tools --no-ask-user --no-auto-update (so it never blocks on a prompt), and disables copilot's flaky
builtin GitHub-API MCP by default for predictable latency (COPILOT_GITHUB_MCP=1 re-enables it).
Continue is deterministic: copilot's --session-id <uuid> both sets a new session's id and
resumes an existing one, so the bridge generates the UUID itself, pins it to the workspace, and
resumes that exact session — falling back after a restart to the newest on-disk session
(~/.copilot/session-state/<id>/workspace.yaml) whose recorded cwd matches.
Cursor. cursor-agent -p --output-format text --trust "<prompt>" runs a prompt non-interactively
and writes the clean final answer straight to stdout — the bridge reads it there, no scraping
(--trust trusts the workspace so it never blocks on a prompt). Continue is deterministic and
race-free: cursor-agent create-chat mints a fresh chat and prints its id, so the bridge mints the
id itself, pins it to the workspace, and resumes that exact chat with -p --resume <chatId> — no
rollout-scraping. After a restart it falls back to the newest on-disk chat under
~/.cursor/chats/<md5(workspace)>/<chat-id>/ whose meta.json cwd matches (the chat-dir hash is
itself md5 of the workspace path).
Set up in 60 seconds
Prerequisites — install whichever backend(s) you want, and sign in once each:
- Antigravity: install
agyand sign in to Antigravity once (via the IDE oragy -i). - Codex: install
codexand runcodex loginonce (ChatGPT account or API key). - Copilot: install
copilot(npm i -g @github/copilot, orwinget install GitHub.Copilot) and runcopilotthen/loginonce (or set aCOPILOT_GITHUB_TOKEN/GH_TOKENenv var). - Cursor: install
cursor-agent(curl https://cursor.com/install -fsSL | bash) and runcursor-agent loginonce (or set aCURSOR_API_KEYenv var).
You don't need all four — the tools for a missing CLI simply report "not found" via their *_status
tool.
Recommended — no clone, you control updates
With uv installed, register the bridge straight from
PyPI under mcpServers in ~/.claude.json — no
path to hardcode, no git pull to remember:
"agent-intern": {
"command": "uvx",
"args": ["agent-intern"]
}
uvx pins to the version it first caches and does not auto-upgrade, so you never run an update you didn't choose — important, since the bridge runs unsandboxed code: a surprise (or compromised) release can't execute until you opt in. When the startup check warns that a newer release is out, upgrade deliberately and restart Claude Code:
uvx agent-intern@latest # fetch + run the newest release (refreshes uv's cache)
[!TIP] Prefer hands-off auto-updates? Put
"args": ["agent-intern@latest"]in the config instead — every launch runs the newest release. Convenient, but it pulls new code without asking each time.
From source
Clone it instead if you want to hack on the bridge or pin a local copy:
git clone https://github.com/SinanTufekci/agent-intern.git
cd agent-intern
pip install fastmcp
python test_smoke.py # 4 real round-trips (ask, continue, image, swarm) — prints four PASS lines
[!NOTE] The smoke test costs a tiny bit of quota and takes ~30–60 s. It exercises the Antigravity path.
Then point Claude Code at the absolute path to server.py under mcpServers in ~/.claude.json:
"agent-intern": {
"command": "python",
"args": ["C:\\path\\to\\server.py"]
}
"agent-intern": {
"command": "python3",
"args": ["/path/to/server.py"]
}
Restart Claude Code. Fifteen tools appear, each prefixed mcp__agent-intern__:
- Antigravity (5):
antigravity_ask,antigravity_continue,antigravity_image,antigravity_image_swarm,antigravity_status - Codex (3):
codex_ask,codex_continue,codex_status - Copilot (3):
copilot_ask,copilot_continue,copilot_status - Cursor (3):
cursor_ask,cursor_continue,cursor_status - Shared (1):
agent_swarm— fans a list of tasks out across all four backends in one run
The single-prompt tools — Antigravity, Codex, Copilot, and Cursor — take a watch=true flag
for the live browser view (Watch mode).
[!NOTE] Your client learns how to use the bridge on its own. The server ships MCP instructions — a short routing guide (when to reach for each tool, which backend to pick, and to pass
workspaceso the sub-agent has repo context) that a client like Claude Code injects into the model's context on connect, as an "MCP Server Instructions" block. So the host model knows how and when to drive these tools without you explaining them — you can just ask for the result.
"Use antigravity_ask to summarize the README of this repo in three bullets." → Claude routes the prompt through the bridge, agy reads the file under the workspace root, and the answer comes back as a plain string. Swap in
codex_ask,copilot_ask, orcursor_askto have GPT, Copilot, or Cursor do the same.
Tools
🛰️ Antigravity
| Tool | Purpose |
|---|---|
antigravity_ask(prompt, workspace?, model?, timeout_s?=180, watch?=false) |
Start a new Antigravity conversation. model selects the model (agy's --model, e.g. "claude-sonnet-4-6"); validated against agy models, defaults to your settings.json model. watch=true opens the live browser view (Watch mode). |
antigravity_continue(prompt, workspace?, model?, timeout_s?=180, watch?=false) |
Continue the conversation rooted at workspace (pinned by id). agy's model is per-invocation, so model can differ from the original ask. watch=true opens the live view. |
antigravity_image(prompt, output_path?, workspace?, timeout_s?=240, watch?=false) |
Generate an image; saves the file (extension corrected to the real bytes) and returns its path + format/size. watch=true streams progress and shows the image inline. |
antigravity_image_swarm(prompts, output_paths?, workspaces?, max_concurrency?=4, timeout_s?=240, watch?=false) |
Generate several images in parallel (one worker per prompt). |
antigravity_status() |
Setup diagnostics: the bridge's own version + whether a newer release is available, plus agy version/compat, state dirs, and newest-transcript readability. Spends no quota. |
🤖 Codex
| Tool | Purpose |
|---|---|
codex_ask(prompt, workspace?, sandbox?="read-only", model?, timeout_s?=180, watch?=false) |
Start a new Codex session. sandbox is a real boundary (see Codex bridge); model selects the model (-m). watch=true opens the live view, streaming codex's steps from its --json event stream. |
codex_continue(prompt, workspace?, timeout_s?=180, watch?=false) |
Continue the Codex session rooted at workspace — resumes the exact session id, falling back to the newest on-disk session for that cwd after a server restart. The resumed session keeps its original sandbox and model. watch=true opens the live view. |
codex_status() |
Setup diagnostics: codex version, login status (codex login status), sessions dir. Spends no quota. |
🐙 Copilot
| Tool | Purpose |
|---|---|
copilot_ask(prompt, workspace?, sandbox?="read-only", model?, timeout_s?=180, watch?=false) |
Start a new Copilot session. sandbox maps to copilot's tool/path permissions (best-effort, not an OS sandbox — see Copilot bridge); model selects the model (--model). watch=true opens the live view, streaming copilot's steps from its --output-format json event stream. |
copilot_continue(prompt, workspace?, sandbox?="read-only", timeout_s?=180, watch?=false) |
Continue the Copilot session rooted at workspace — resumes the exact self-set session id, falling back to the newest on-disk session for that cwd after a restart. Unlike Codex, sandbox applies here too (copilot re-applies permissions each turn). watch=true opens the live view. |
copilot_status() |
Setup diagnostics: copilot version, an auth hint (no login status command exists, so best-effort), session-state dir. Spends no quota. |
✳️ Cursor
| Tool | Purpose |
|---|---|
cursor_ask(prompt, workspace?, sandbox?="read-only", model?, timeout_s?=180, watch?=false) |
Start a new Cursor chat. sandbox maps to cursor's mode/force flags (agent-enforced, not an OS sandbox — see Cursor bridge); model selects the model (--model, validated against cursor-agent models). watch=true opens the live view, streaming cursor's steps from its --output-format stream-json event stream. |
cursor_continue(prompt, workspace?, sandbox?="read-only", timeout_s?=180, watch?=false) |
Continue the Cursor chat rooted at workspace — resumes the exact chat id the bridge minted (create-chat + --resume), falling back to the newest on-disk chat for that cwd after a restart. watch=true opens the live view. |
cursor_status() |
Setup diagnostics: the bridge's own version + whether a newer release is available, plus cursor version and login status (cursor-agent status). Spends no quota. |
🐝 Shared
| Tool | Purpose |
|---|---|
agent_swarm(tasks, max_concurrency?=4, timeout_s?=180, watch?=false) |
Run several tasks in parallel across all four backends — each task names its backend (antigravity, codex, copilot, or cursor) plus a prompt (an optional model for any backend, and sandbox for Codex/Copilot/Cursor). Every answer comes back in one block; watch=true opens the live dashboard (Swarm). |
workspace defaults to the MCP server's current working directory. Point it at a real project dir
for context-aware answers — every backend gives the model access to files under that root (Codex,
Copilot, and Cursor honoring their sandbox).
antigravity_image forces agy to save to an explicit absolute path — without one, agy
falls back to its own scratch dir (~/.gemini/antigravity-cli/scratch/). It then
corrects the file extension to match the real bytes: agy's image model picks the
format itself (JPEG for photo-like images, PNG for flat graphics), so a requested
out.png may come back as out.jpg. The returned path always reflects the true
format.
🤖 Codex bridge — the well-behaved sibling
codex exec writes its final message to a file the bridge asks for via -o/--output-last-message,
so the answer comes back without any scraping (where agy needed a transcript workaround before 1.0.15
fixed its stdout). Three things make Codex worth reaching for over Antigravity:
- Real sandbox.
sandboxacceptsread-only(default — reads and answers, writes nothing),workspace-write(may edit files under the workspace), ordanger-full-access(no sandbox — avoid). Unlike agy's no-op--sandbox, codex's-sactually enforces this.codex exechas no interactive approval gate, so this flag is your safety boundary — opt into write access deliberately. - Model selection works.
modelmaps to codex's-m. (agy's--modelworks in print mode too as of 1.0.16; all four backends now expose the samemodelknob.) - Stronger reasoning. Codex is a coding agent, not an image model — there's no
codex_image. Its strength is reasoning and real code/repo work; hand it the jobs that need a heavier model.
Auth. Uses your existing Codex login (ChatGPT account or API key). Run codex login once; check
with codex_status. No new keys for the bridge to manage.
[!WARNING]
codex execruns the model as an autonomous agent with no interactive approval gate. Thesandboxflag (defaultread-only) is the real boundary, butworkspace-write/danger-full-accesslet it modify files — and a swarm runs N agents at once. Only use it with trusted prompts on trusted content.
🐙 Copilot bridge — GitHub's agentic coder
The GitHub Copilot CLI (copilot, from @github/copilot) is stdout-native like Codex:
copilot -p "<prompt>" -s runs a prompt non-interactively and prints just the final answer to
stdout, so the bridge reads it there — no scraping. What makes it worth reaching for:
- Model selection.
modelmaps to copilot's--model(e.g.gpt-5.3-codex,claude-sonnet-4.6, orauto). An unavailable model errors immediately with a clear message. - Deterministic, race-free continue. copilot's
--session-id <uuid>both sets a new session's id and resumes an existing one, so the bridge generates the UUID itself and pins it to the workspace — no rollout-scraping. After a restart it falls back to the newest on-disk session (~/.copilot/session-state/<id>/workspace.yaml) whose recordedcwdmatches. - Fast by default. Runs with
--allow-all-tools --no-ask-user --no-auto-update, and disables copilot's builtin GitHub-API MCP (--disable-builtin-mcps) because its flaky HTTP connect can stall a call up to ~60 s. SetCOPILOT_GITHUB_MCP=1to keep it (for Copilot's issue/PR/repo tools).
Sandbox is best-effort, not enforced. Unlike Codex's OS sandbox, copilot's boundary is
tool/path permissions. The sandbox knob maps to copilot flags for a uniform cross-backend field:
read-only(default) — auto-approves tools so it runs headless, then denies the localwriteandshelltools (--deny-tool). Best-effort: it is not an OS sandbox, and network/MCP tools can still act. For a hard read-only boundary, usecodex_askinstead.workspace-write— writes allowed, but file access stays confined to the workspace (no--allow-all-paths).danger-full-access—--allow-all(tools + all paths + all URLs). Avoid.
Auth. Uses your existing Copilot login — run copilot then /login once (stored in the OS
credential store), or set COPILOT_GITHUB_TOKEN/GH_TOKEN/GITHUB_TOKEN for headless use. Check
with copilot_status. If copilot isn't on PATH (the winget install can land off a stale PATH),
set COPILOT_BIN to its full path — e.g.
%LOCALAPPDATA%\Microsoft\WinGet\Packages\GitHub.Copilot_*\copilot.exe.
[!WARNING]
copilot -pruns the model as an autonomous agent with--allow-all-tools(required to run headless). Itssandboxis best-effort tool/path permissions, not an OS sandbox — safer than agy, weaker than Codex'sread-only. Only use it with trusted prompts on trusted content.
✳️ Cursor bridge — the widest model menu
Cursor's agent CLI (cursor-agent, from cursor.com/cli) is stdout-native
like Codex and Copilot: cursor-agent -p --output-format text --trust "<prompt>" runs a prompt
non-interactively and writes just the final answer to stdout, so the bridge reads it there — no
scraping (--trust trusts the workspace so it won't block on a prompt). What makes it worth reaching
for:
- The widest model menu.
modelmaps to cursor's--model(e.g.gpt-5.2,sonnet-4-thinking,auto, and parameterized ids likeclaude-opus-4-8[context=1m]) — GPT, Claude, Grok, and Composer in one place. The bridge validates the label againstcursor-agent modelsand rejects a typo up front (like agy). Omitmodelto use your Cursor account default. - Deterministic, race-free continue.
cursor-agent create-chatmints a fresh chat and prints its id, and-p --resume <chatId>resumes that exact chat — so the bridge mints the id itself, pins it to the workspace, and resumes deterministically (no rollout-scraping, same idea as Copilot's self-set session id). After a restart it falls back to the newest on-disk chat under~/.cursor/chats/<md5(workspace)>/<chat-id>/whosemeta.jsoncwdmatches (the chat-dir hash is itself md5 of the workspace path).
Sandbox is agent-enforced, not an OS sandbox. Like Copilot, cursor's boundary is which tools the
agent can reach, not an OS jail. The sandbox knob maps to cursor's mode/force flags for a uniform
cross-backend field:
read-only(default) —--mode ask: thewriteandshelltools are unavailable, so cursor analyzes and answers but makes no edits (verified: it refuses to write files). Agent-enforced and best-effort — it is not an OS sandbox. For a hard read-only boundary, usecodex_askinstead.workspace-write—--force: edits and commands allowed, file access rooted at--workspace.danger-full-access—--force --sandbox disabled(OS sandbox off). Avoid.
(Cursor also exposes an OS-level --sandbox enabled/disabled; the bridge drives the uniform field via
mode/force.)
Auth. Uses your existing Cursor login — run cursor-agent login once (OS credential store), or
set CURSOR_API_KEY for headless use. Check with cursor_status. If cursor-agent isn't reliably on
PATH (the installer drops a cursor-agent.CMD shim a bare name can't launch on Windows), set
CURSOR_BIN to its full path — mirrors the AGY_BIN/CODEX_BIN/COPILOT_BIN overrides.
[!WARNING]
cursor-agent -pruns the model as an autonomous agent with--trust(and--forcewhen writes are allowed). Itssandboxis agent-enforced (read-only makes the write/shell tools unavailable), not an OS sandbox — safer than agy, weaker than Codex'sread-only. Only use it with trusted prompts on trusted content.
👁️ Watch mode — Agent Intern (experimental)
Pass watch=true to any single-prompt tool — antigravity_ask, antigravity_continue,
antigravity_image, codex_ask, codex_continue, copilot_ask, copilot_continue, cursor_ask,
or cursor_continue — to watch
the agent work live in a little chat-style browser window called Agent Intern. The agent
still runs headless; alongside it the bridge serves a tiny page on 127.0.0.1 and opens it in a
small, chromeless app window that renders the exchange as a conversation: your prompt shows as a
chat bubble, the agent's live steps stream in a collapsible "thinking" trace — its planner narration
(▸), the real commands it runs ($), and completions (✓), read live (from agy's transcript, or
codex's / copilot's JSON event stream, or cursor's --output-format stream-json) — and the final
answer arrives as a Markdown card (and, for
antigravity_image with watch=true, the generated image shown inline). A *_continue run
opens with the prior turns of the conversation shown as history, so it reads as one ongoing
thread rather than a blank new window. (A watched cursor_continue is the exception — Cursor stores
its transcript in an opaque SQLite blob, so its window opens without visible prior-turn history.)
- Cross-platform & best-effort. Prefers a Chromium browser (
--appmode) for the windowed look; falls back to a normal browser window. If nothing can open, the run still completes and returns normally. - Window size. Set
AGY_WATCH_WINDOW_SIZE(e.g.AGY_WATCH_WINDOW_SIZE=480,700) to resize the window; default is560,760. Press Enter / Esc in the window to close it. - One window, reused — but concurrent runs stay separate. Repeated sequential
watch calls reuse the already-open window instead of stacking a new one (the open
page resets itself for the new run; the swarm dashboard rebuilds for the new fan-out).
A run that starts while another watched run is still working gets its own
window instead — so two concurrent single-worker runs (e.g. a
codex_askand acopilot_askat once) each stream into their own view and never clobber each other. If you closed the window, the next run opens a fresh one. SetAGY_WATCH_ALWAYS_NEW=1to force a new window every time. - Chat layout & history. Prompts render as chat bubbles (labelled CLAUDE, since the MCP
client writes them) — long ones clamp to a few lines with a show more / show less toggle — and
answers as Markdown cards tagged with the backend (AGY / CODEX / COPILOT / CURSOR). A
*_continuerun seeds the window with the conversation's prior turns, read from each backend's own session store (agy's transcript, codex's rollout, copilot'sevents.jsonl; Cursor's store is opaque, so a watchedcursor_continueopens without visible history). The swarm's per-worker detail window uses the same chat design for its one task. - Progress, keyboard & copy. Each panel shows a time progress bar (elapsed / timeout). The swarm dashboard adds an overall done/total bar and per-row time bars; use ↑/↓ to select a worker and ↵ to open its detail window. Answers render as Markdown with a copy button, and a "jump to latest" badge appears if you scroll up.
- Coarse, not token-level. The backends flush their step stream in chunks, so you get a handful of live steps, not character streaming. The returned value is identical to the non-watch call. Nothing is sent anywhere but your own machine.
🐝 Swarm — run agents in parallel
agent_swarm fans a list of tasks out to workers that run truly
concurrently (capped at max_concurrency, default 4), then returns every
worker's result in one block. Each task names its own backend, so a single
swarm can mix Antigravity (Gemini), Codex, Copilot, and Cursor workers — hand the
reasoning-heavy jobs to Codex, Copilot, or Cursor and the quick ones to Gemini, all at
once. Good for independent sub-tasks: summarise N files, ask the same question
about N repos, fix N bugs. (antigravity_image_swarm stays separate — it
generates N images, and only agy has an image model.)
agent_swarm(tasks=[
{"backend": "antigravity", "prompt": "Summarise src/auth.py in 2 bullets."},
{"backend": "codex", "prompt": "Find and fix the failing test in tests/",
"sandbox": "workspace-write", "workspace": "./repo"},
{"backend": "copilot", "prompt": "Explain what src/api.py exposes.",
"sandbox": "read-only", "workspace": "./repo"},
{"backend": "cursor", "prompt": "Draft a docstring for src/utils.py.",
"model": "auto", "workspace": "./repo"},
])
How it stays correct under concurrency. The single-agent agy tools serialize
through a lock because agy rewrites last_conversations.json on every call, so
concurrent runs sharing one state dir would race. The swarm sidesteps this: each
agy worker runs with its own isolated HOME/USERPROFILE, so agy's
brain/, cache/, and last_conversations.json never collide — no lock needed.
Auth still works because agy reads it from the OS credential store, not from
~/.gemini (verified on agy 1.0.9). Codex, Copilot, and Cursor workers need no such
isolation — each is a fresh one-shot (codex exec with its own -o file; copilot -p with its own self-set session id; cursor-agent -p with its own minted chat id). Each worker's cwd is its real workspace,
so file access is unchanged. Measured ~2.8× speedup at 3 agy workers (the AI Pro
backend does not serialize per-account); higher max_concurrency trades
quota/rate-limit pressure for wall-clock.
- Per-task fields —
backend(antigravity/codex/copilot/cursor) andpromptare required;workspacedefaults to the server cwd;sandboxandmodelapply to Codex, Copilot, and Cursor (ignored for Antigravity). Swarm workers are one-shot — there is no*_continuefor a swarm worker's session. - Error isolation — a worker that fails is reported in place; the others still return.
watch=true— opens a thin live Agent Swarm dashboard (one row per worker, with a backend badge, repo, prompt, and latest step). Click a row to pop that agent into its own window streaming its full step log.
[!WARNING] A swarm launches N unsandboxed agents at once — N× the prompt-injection "lethal trifecta" surface of a single call (see Security). Only use it with trusted prompts on trusted content. Codex workers honor their enforced
sandbox; Copilot and Cursor workers honor their best-effortsandbox; Antigravity workers have no real boundary.
Model & auth
| 🛰️ Antigravity | 🤖 Codex | 🐙 Copilot | ✳️ Cursor | |
|---|---|---|---|---|
| Model | Selectable via the model argument (agy's --model, e.g. "gemini-3.1-pro-high", "claude-sonnet-4-6"); omit to use the "model" field in agy's settings.json (gemini-3.5-flash-high by default). agy 1.1.5 replaced the old human labels with these slugs — the old "Gemini 3.1 Pro (High)" form no longer works. Switching model in -p used to hang (through ~1.0.14) but is fixed as of 1.0.16. An unknown model was silently ignored through 1.1.1 and hard-fails in -p as of 1.1.2; either way the bridge validates it against agy models and rejects a typo up front. Flash High is speed-optimized for cheap tool-calling; pick a bigger model for heavier work. |
Selectable via the model argument (codex's -m). codex does not hang on a switch, so model choice is a first-class knob. |
Selectable via the model argument (--model, e.g. gpt-5.3-codex, claude-sonnet-4.6, auto); omit for your account default. An unavailable model errors immediately. |
Selectable via the model argument (--model, e.g. gpt-5.2, sonnet-4-thinking, auto, or parameterized ids like claude-opus-4-8[context=1m]); a wide GPT/Claude/Grok/Composer menu, validated against cursor-agent models (a typo is rejected up front). Omit for your Cursor account default. |
| Auth | Piggybacks whatever credential store agy uses on your OS (Windows Credential Manager, macOS Keychain, libsecret on Linux — the bridge never touches it directly). Log in once; every call silent-auths on the same AI Pro quota you already pay for. |
Uses your existing Codex login — ChatGPT account or API key. Run codex login once; verify with codex_status. |
Uses your existing Copilot login — run copilot then /login once (OS credential store), or set COPILOT_GITHUB_TOKEN/GH_TOKEN/GITHUB_TOKEN. Verify with copilot_status. |
Uses your existing Cursor login — run cursor-agent login once (OS credential store), or set CURSOR_API_KEY. Verify with cursor_status. |
⚠️ Security
All four backends run the model as an autonomous agent. The difference is whether you get a real boundary: Codex enforces one, Copilot and Cursor offer best-effort ones, Antigravity offers none.
Antigravity — no usable boundary
agy -p executes its own tools — reading and writing files, running shell commands, reaching
the network — with no approval gate. Through agy 1.1.2 that was simply how print mode worked,
with no opt-out at all. As of 1.1.3 it is a choice the bridge makes: agy finally gates headless
tool calls, and the bridge deliberately opts out with --dangerously-skip-permissions, because a
gated -p can do no useful work (it soft-denies even a plain file read, and print mode has no way
to prompt). The posture below is therefore unchanged — assume every call runs arbitrary
No comments yet
Be the first to share your take.