Arm
Type @Cheap Labor in any ChatGPT chat and confirm the project. That single invocation is the only trigger — the bridge stays dormant until it's invoked.
So Cheap Labor splits the work: ChatGPT plans, edits, and reviews on its own allowance, while Codex spends its pool only on real implementation — over your local repo, from a single @cheap-labor trigger.
Why
Codex usage is a limited pool, and most of what an agent does is not writing code. Reading files, exploring the repo, planning, and reviewing diffs all burn the allowance — the pool empties before real work ships. ChatGPT and Codex bill separately, so Cheap Labor splits the job at the seam.
billed to ChatGPT's allowance
Reads your repo, plans in detail, and makes small edits itself. The free bridge tools handle the reading, planning, and one-file changes without ever touching the Codex pool.
spent only on real implementation
Runs only when a plan is ready. Executes the steps literally, runs the build and tests, fixes what breaks, and hands back the diff for review.
Workflow
One trigger arms the session. Every step after that is visible — you watch the transcript, and you approve the moves.
Type @Cheap Labor in any ChatGPT chat and confirm the project. That single invocation is the only trigger — the bridge stays dormant until it's invoked.
git_status, list_tree, read_file, and grep map the repo. All free — the Codex pool is untouched.
ChatGPT writes exact step-by-step instructions into .codex-bridge/: which files to create or edit, what each change should be, which commands to run, and how to verify.
One-file changes go in directly with write_file and edit_file. Still free.
When the plan is ready, implement hands it to Codex in a workspace-write sandbox. It works through the steps, runs the build and tests, and fixes what breaks.
ChatGPT reads the returned git diff and sends targeted corrections back through the same loop.
Safety
An agent with write access to your machine earns its guardrails, not your trust.
Provably safe reads run freely. File deletes, git rewrites, and network installs always ask. Everything else follows the approval mode.
normal asks before every command. auto lets ChatGPT judge safe commands itself — dangerous ones still come back to you.
Tools refuse paths outside the session-approved project. Git-backed tools require the project to be the repository root.
File reads, greps, diffs, and command output redact known secret patterns by default.
HEAD and the working tree are snapshotted before every heavy run. Rollback restores a checkpoint, and is itself undoable.
Commits stay local and never push. Push, pull, reset, rebase, and checkout are never exposed.
Interactive guardrail
Switch modes to see how the same command is handled before it touches your project.
Install
macOS and Linux, no public ports — the Secure MCP Tunnel is outbound-only, so nothing on your machine is exposed.
Then open ChatGPT, type @cheap-labor, and confirm the project you want to work on. Approvals default to normal — switch to auto in chat any time.