Learning path map
Detailed content
🤝 Claude uses Codex
Recipe R1: the codex-exec.sh bridge lets Claude ask Codex for a second opinion or a task without leaving Claude Code.
A kit script, runtime/pontes/codex-exec.sh, that wraps codex exec: sends a request to Codex and returns the response.
It’s the official route (CLI, level 3) for what mod videos did behind the scenes in the app.
Bridge, CLI, codex exec, second opinion.
Grant the script execute permission and ask Codex to respond only with PONG.
Testing the bridge outside the agent separates a bridge problem from a request problem.
chmod +x, proof, PONG.
The R1 prompt: Claude uses the bridge to have Codex review README.md, then compares that review with its own opinion.
Two different models make mistakes in different places; the comparison shows what one model alone would miss.
Cross-review, read (N4), combine the answers.
Pass the folder and workspace-write mode to Codex so it can create notas.txt with the word OK.
Changing files is N3: only when you ask, and the proof is that cat notas.txt shows OK.
Sandbox, read-only, workspace-write, N3.
The bridge only accepts read-only and workspace-write; requesting danger-full-access returns "sandbox rejected by POLITICA".
Seeing the refusal happen gives you confidence that the rule is in the code, not just on paper.
POLITICA.md, refusal, exit code 2, per-action limit.
The bridge variables (default model gpt-6-luna, default time of 600 seconds) and the “If something goes wrong” section of R1.
The bridge stopping, sandbox refusal, and blocked network each have a known cause and a one-line fix.
Environment variable, timeout, stdin, LIMITES.md.
🔌 Your first MCP bridge
Recipe R3: a dependency-free MCP server turns Clara’s schedule and Sônia’s sales CSV into tools for the agent.
A standard way for a program to offer named tools and rules to any compatible agent.
The same bridge works with Claude Code and Codex: a local bridge (level 6) exposed through MCP (level 2).
MCP, server, tool, stdio.
listar_horarios_livres reads agenda.csv; resumo_vendas reads erp-vendas.csv and adds up by customer or product.
These are the two most common cases of systems without an API: a spreadsheet calendar and an ERP that only exports data.
agenda.csv, erp-vendas.csv, read-only (N4).
Run server.mjs with --selftest and see tools: 2, free time slots on 06/10, and TOTAL: R$ 856.00.
Test the bridge without any agent and without using up your quota.
Self-test, proof, result checked by hand.
The root .mcp.json already registers the bridge, and .claude/settings.json already allows it; claude mcp list confirms this.
Knowing where the connection is registered lets you replace it later with your own system.
.mcp.json, enabledMcpjsonServers, Pending approval.
Ask Claude for available times on 2026-10-07 and get 08:00 (Dr. Ana) and 16:00 (Dr. Bruno).
That’s Clara checking the calendar without opening the spreadsheet, and the answer matches the available rows in the CSV.
claude -p, tool call, proof from the source.
One command registers the ponte-modelo bridge in Codex, with the full path to server.mjs.
One bridge, two agents: you write the tool once and use it in both.
codex mcp add, absolute path, $PWD.
🏗️ Your system’s bridge
Step 4 of R3: point the ponte-modelo bridge to your system’s export, change the columns, and keep everything read-only.
Find the file it exports in the system menu, with a header and in a fixed folder.
Without an API, the export is the bridge's raw material; its format determines how much adjustment will be needed.
Export, header, delimiter, fixed folder.
The PONTE_DADOS variable in the env field of .mcp.json, which makes the bridge read your folder instead of the examples.
Change the data source without touching the bridge code.
Environment variable, .mcp.json, env field.
A prompt that tells the agent to change only the column names used in run(), showing the before and after.
You adapt the bridge without coding, and the account rule stays the same.
run(), column name, limit stated in the request.
The R3 rule: a tool that reads is N4; a tool that writes counts as "modify" in POLITICA.md and requires approval first.
A read error gives you the wrong answer; a write error corrupts data that other people use.
N4, N2, readFileSync, separate tool.
Recalculate with a calculator the total the bridge calculates, line by line and by client.
A wrong column doesn’t cause an error: it gives you the wrong number that looks right.
A verification account: proof, command → expected output.
One line in the map with the path, level 6, the tool, the read policy (N4), and the test date.
A system without an entry isn’t used by the agent; the dated entry is what enables its use.
CAPACIDADES.md, tested in, pending line.
🌐 Browser with policy
Recipe R5: agent-browser for systems that exist only as websites, with a written rule describing what the agent reads, fills in, and never does.
Computer use is step 5 on the ladder, the only one with low stability: the site changes and the automation gets lost.
If an API, MCP, CLI, or export is available, it takes precedence over the browser.
Computer use, stability, selector.
Two commands: install agent-browser with npm and download the Chromium it uses.
A separate browser without your logins is the safest way to get started.
npm, Chromium, Claude in Chrome.
Open example.com, read the title, and close it; the proof is the output Example Domain.
You verify the browser without clicking anything or sending anything.
open, get title, close, R5 proof.
The R5 request: read a website’s price table and return it as CSV, without clicking Submit or Purchase.
Reading is N4, filling in or sending is N2, and paying is N1; the request already says where to stop.
Limit in the request, N4, N2, N1.
The "Browser:" block from R5 pasted into AGENTS.md, which Codex reads and CLAUDE.md points to.
The rule applies to every request, even one you forgot to limit.
AGENTS.md, @AGENTS.md, permanent rule.
You log in; the agent doesn't ask for or store your password, and credentials don't pass from one tool to another.
In a logged-in browser, the agent can access everything you can.
Credential, logged-in browser, POLITICA.md.