amicus
Give your coding agent a second opinion from a different model.
amicus is one MCP server that fronts Codex, Kimi and Claude. The backend is a parameter, not a separate installation — so instead of running three servers and learning three tool surfaces, you ask for a consult, a review, or a delegated task and say which model should answer.
- Consult — a read-only second opinion on an approach, a bug, or a design.
- Review — a structured review of changes gathered from git, with findings tied to evidence.
- Delegate — a task implemented in a throwaway git worktree, returned as a diff you review. It is never applied to your working tree.
- Adversarial review — a fixed critic aimed at a plan, claim, or decision.
Long-running calls can be started in the background and polled, so a broad review does not block your session.
Install
Claude Code
/plugin marketplace add briandconnelly/amicus
/plugin install amicus@amicus
Codex
codex plugin marketplace add briandconnelly/amicus
codex plugin add amicus@amicus
Start a new session afterwards so the host loads the bundled skill and tools.
Any other MCP client
The plugins launch the server from a published release tag, pinned in
.mcp.json. Point your client at the same command:
{
"mcpServers": {
"amicus": {
"command": "uvx",
"args": ["--from", "git+https://github.com/briandconnelly/amicus.git@v0.2.0", "amicus-mcp"]
}
}
}
Requirements
- Python 3.11 or newer, and
uv. - The CLI for each backend you enable, installed and authenticated:
codex,kimi,claude. amicus drives those CLIs; it does not talk to the providers itself, and it stores no credentials.
Using it
Choose which backends are available with AMICUS_BACKENDS — a comma-separated list of codex,
kimi and claude. Only the backends you name are enabled.
Then just ask, in your own words:
- "Get a second opinion on this approach from another model."
- "Have another model review my current changes."
- "Delegate this task to another model and show me the proposed diff."
In Claude Code there are also slash commands:
| Command | What it does |
|---|---|
/amicus:consult |
Ask another model for a read-only second opinion |
/amicus:review |
Have another model review your git changes |
/amicus:delegate |
Delegate a coding task; get back a reviewable diff |
/amicus:delegate-async |
Delegate a long coding task in the background; get a job id to poll with /amicus:jobs |
/amicus:adversarial |
Run a fixed adversarial critic against a plan, claim, or decision |
/amicus:dry-run |
Preview what a review or delegate call would send — free, no model call |
/amicus:jobs |
Poll, fetch, list, or cancel a background job |
/amicus:status |
Check which backends are enabled, installed, and authenticated |
Start with /amicus:status — it tells you which backends are actually usable before you spend
anything.
The tools
Nineteen tools, in five groups, one of them a deprecated alias. Everything paid has a free way to inspect it first.
| Group | Tools |
|---|---|
| Discovery — free | amicus_backends, amicus_capabilities, amicus_models |
| Verbs — paid | amicus_consult, amicus_review_changes, amicus_delegate, amicus_adversarial_review |
| Previews — free | amicus_review_changes_dry_run (review), amicus_delegate_dry_run; amicus_dry_run is the review preview's deprecated alias, removed at or after 0.5.0 |
| Background twins — paid | the four verbs again, each with an _async suffix |
| Jobs — free | amicus_job_status, amicus_job_result, amicus_job_consume_result, amicus_job_list, amicus_job_cancel |
Not every backend does everything:
| Verb | Codex | Kimi | Claude |
|---|---|---|---|
consult, review_changes |
yes | yes | yes |
delegate |
yes | yes | no |
adversarial_review |
no | no | yes |
A no is amicus's routing decision, not a claim about the model. delegate is absent on Claude
by a deliberate review-only policy. adversarial_review is scoped to Claude for v1, but the verb
is amicus's own: the prompt it builds and the result shape it returns are amicus's for any
backend, and what Claude contributes is a critic stance layered on top. So nothing about
Codex or Kimi stops either from reviewing adversarially — ask them through consult or
review_changes and supply the adversarial stance yourself. What the verb adds is that stance
fixed, plus its target and evidence carriers.
Asking a backend for something it does not support returns a feature_unsupported error naming
the backend and the feature, rather than failing obscurely.
Safety
- A delegated diff is never applied. It runs in a throwaway git worktree and comes back for you to read and apply yourself.
- Every verb call spends the selected backend's quota. The dry runs and the discovery and job tools do not.
- Enabling a backend that can write makes the tool surface carry that backend's approval
annotations — see
docs/MIGRATION.md. - Your prompts go to whichever provider you selected, through that provider's own CLI. Each
backend discloses how it carries your text — visible on
amicus_backends.
Configuration
AMICUS_BACKENDS is the one most people set. Beyond it, each backend takes an optional model,
reasoning effort, and binary path (AMICUS_CODEX_MODEL, AMICUS_KIMI_REASONING_EFFORT,
AMICUS_CLAUDE_BIN, and so on), and there are limits for timeouts, job retention and payload
sizes. The full list is the env_vars array in .mcp.json.
Logging goes to stderr, and AMICUS_LOG_FILE mirrors amicus's own records to a file. The
fastmcp and mcp libraries' records also reach stderr, but never below WARNING whatever
AMICUS_LOG_LEVEL says, never the file, and with every unaudited FastMCP server record
reduced to its level, logger and exception type. That is deliberate (ADR 0023): those
libraries can log a caller's prompt text, so a FastMCP-side failure is diagnosed from the
exception type and frames rather than its message.
Coming from codex-in-claude, moonbridge, or claude-in-codex
amicus replaces all three. docs/MIGRATION.md maps the old tool names onto
the new ones.
Status and known limits
0.3.0 is the current release, and it is a breaking one: the discovery surface moved from
amicus/0.1/schema-13 to amicus/0.1/schema-30 and stored job results from RESULT_FORMAT 4 to
6, so a job result 0.2.0 stored cannot be read after upgrading.
docs/MIGRATION.md walks through what a caller written
against 0.2.0 has to change, and CHANGELOG.md lists everything that moved. The
server's wire contract is exercised by the test suite and by host captures against Claude Code and
Codex, but:
- Two router-skill evaluation scenarios are unresolved — S6 (diff-safety wording) and S7 (approval
friction) — recorded in
docs/adr/0012-m6-packaging-decisions.md. Neither is a defect in the server's wire contract. - A third-party backend distribution loads through the
amicus.backendsentry-point group, but cannot yet be enabled or called:AMICUS_BACKENDSand thebackendparameter accept only the in-tree ids.
Development
uv sync
uv run prek install --prepare-hooks # one-time local hooks
The gate is defined once, in AGENTS.md (Rules, item 2); CI runs it on every supported Python
version.
| Question | Read |
|---|---|
| What is being built and why | docs/superpowers/specs/2026-09-04-amicus-design.md |
| How milestones are executed by agents | docs/superpowers/plans/2026-09-04-amicus-execution-model.md |
| Architecture decisions | docs/adr/ |
| How a release is cut | docs/RELEASING.md |
| Deprecating the sibling projects | docs/DEPRECATING-SIBLINGS.md |
| The router skill an agent loads to call amicus | skills/collaborating-with-amicus/ |
| Host captures and CLI evidence | docs/host-captures/, docs/claude-help/, docs/kimi-help/ |
| How past milestones were built | git history — executed plans are removed once merged |
License
MIT. See LICENSE.
Release files for amicus 0.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| amicus-0.3.0.tar.gz | 1.4 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| amicus-0.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 1.6 MB
Release files / amicus-0.3.0.tar.gz
| Download URL | amicus-0.3.0.tar.gz |
|---|---|
| Size | 1.4 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
628b2956479b57186a15efbaeecd39e2aa63b91c74c460e48077c1f1af84d4e5
|
|
BLAKE2b-256 checksum How to use checksums |
40ca9dacae26392fed8e818f981ad131be556b2efea54fb15b020fc9be90044a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 15, 2026.
Transparency logRelease files / amicus-0.3.0-py3-none-any.whl
| Download URL | amicus-0.3.0-py3-none-any.whl |
|---|---|
| Size | 245.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
7348043306e6e540f4e5ff5d0db8226b7b6f7e08dd482e2eac3c81c5fad9fb79
|
|
BLAKE2b-256 checksum How to use checksums |
f619d956c0591da4724faf397e723d4481fc4f0c032415ceeed3a9bd2d69a958
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 15, 2026.
Transparency log