ChatGPT thinks. Codex executes. They bill separately.

So Cheap Labor splits the work: ChatGPT plans, edits, and reviews on its own allowance, while Codex spends its pool only on real implementation — over your local repo, from a single @cheap-labor trigger.

Two allowances. One cheap laborer.

Codex usage is a limited pool, and most of what an agent does is not writing code. Reading files, exploring the repo, planning, and reviewing diffs all burn the allowance — the pool empties before real work ships. ChatGPT and Codex bill separately, so Cheap Labor splits the job at the seam.

billed to ChatGPT's allowance

ChatGPT — the thinker

Reads your repo, plans in detail, and makes small edits itself. The free bridge tools handle the reading, planning, and one-file changes without ever touching the Codex pool.

read_file grep plan_write edit_file git_diff checkpoint

spent only on real implementation

Codex — the executor

Runs only when a plan is ready. Executes the steps literally, runs the build and tests, fixes what breaks, and hands back the diff for review.

The workflow

One trigger arms the session. Every step after that is visible — you watch the transcript, and you approve the moves.

01

Arm

Type @Cheap Labor in any ChatGPT chat and confirm the project. That single invocation is the only trigger — the bridge stays dormant until it's invoked.

02

Understand

git_status, list_tree, read_file, and grep map the repo. All free — the Codex pool is untouched.

03

Plan

ChatGPT writes exact step-by-step instructions into .codex-bridge/: which files to create or edit, what each change should be, which commands to run, and how to verify.

04

Small edits

One-file changes go in directly with write_file and edit_file. Still free.

05

Implement

When the plan is ready, implement hands it to Codex in a workspace-write sandbox. It works through the steps, runs the build and tests, and fixes what breaks.

06

Review

ChatGPT reads the returned git diff and sends targeted corrections back through the same loop.

Safety by default

An agent with write access to your machine earns its guardrails, not your trust.

Three-bucket commands

Provably safe reads run freely. File deletes, git rewrites, and network installs always ask. Everything else follows the approval mode.

Approval modes

normal asks before every command. auto lets ChatGPT judge safe commands itself — dangerous ones still come back to you.

Project scoping

Tools refuse paths outside the session-approved project. Git-backed tools require the project to be the repository root.

Secrets redacted

File reads, greps, diffs, and command output redact known secret patterns by default.

Checkpoints & rollback

HEAD and the working tree are snapshotted before every heavy run. Rollback restores a checkpoint, and is itself undoable.

Local-only commits

Commits stay local and never push. Push, pull, reset, rebase, and checkout are never exposed.

Interactive guardrail

See the approval gate in action.

Switch modes to see how the same command is handled before it touches your project.

run_command · approval gate
$ npm test
normal modeApproval required before this command runs.

Two commands, then it's wired

macOS and Linux, no public ports — the Secure MCP Tunnel is outbound-only, so nothing on your machine is exposed.

~/your-repo · zsh
$ git clone https://github.com/psrisuphan/cheap-labor.git $ cd cheap-labor $ ./scripts/install.sh # deps · build · tunnel profile · 25 tools validated $ ./scripts/tunnel.sh start # keep it running while you work

Then open ChatGPT, type @cheap-labor, and confirm the project you want to work on. Approvals default to normal — switch to auto in chat any time.

macOS · Linux Node.js ≥ 20 Codex CLI ChatGPT · dev mode
The installer checks every prerequisite, writes your tunnel profile, and walks you through connecting the app to ChatGPT — it points you at the exact platform pages.