
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
codex-delegate-mcp
Advanced tools
MCP bridge that lets Claude Code and other hosts delegate implementation to the OpenAI Codex CLI.
Stop burning your frontier agent's limits on boilerplate.
Delegate implementation to the OpenAI Codex CLI — your agent writes the brief and reviews the diff.
Use your best coding agent where its judgment matters most: understanding the task, shaping the plan, and reviewing the result.
Codex Delegate is the MCP bridge that lets Claude Code, Cursor, Copilot — or any MCP client — hand implementation to the OpenAI Codex CLI, then get a clean, structured result back for review.
Your assistant does what frontier models are actually for: understands the task, writes a precise brief, reviews the finished diff. Codex holds its own as the implementer — guided and checked by a smarter orchestrator. The result reads like frontier work, because a frontier model planned it and signed off on it.
Codex tears through multi-file edits while a frontier chat model would still be streaming the first file. You delegate, keep working with your assistant, and the diff shows up done.
Delegated work runs on the OpenAI Codex CLI and its own usage — separate from your orchestrator's chat quota. Your Claude, Cursor, or Copilot subscription spends tokens on the brief and the review; Codex does the grinding. On API? That's the per-token grind moved off your main bill.


status, the files Codex edited, and per-turn token counts. Fields that carry no signal are omitted, so anything present is worth reading.agent edits, plan requests a schema-validated plan for you to review and approve, ask answers questions, and review runs Codex's own reviewer over uncommitted work, a base branch, or a single commit.resumeThreadId, and get told if the context didn't actually carry over.cancel returns once the process has ended, not once the kill was requested.doctor tool that tells you exactly what's missing if setup isn't right.The caveats are documented rather than buried: what an empty warnings does not prove, and when result is salvage instead of an answer, are in the delegate reference.
You need Node.js 20+ and the OpenAI Codex CLI, already logged in (codex login).
/plugin marketplace add andreilungeanu/codex-delegate-mcp
/plugin install codex-delegate@codex-delegate-mcp
Then just ask:
Delegate to Codex: migrate src/api from callbacks to async/await and update the tests, then walk me through what changed.
That's the whole loop — Claude writes the brief, Codex grinds through the files, Claude walks you through the diff.
Add an MCP server in Cursor Settings → MCP (or project .cursor/mcp.json):
{
"mcpServers": {
"codex-delegate": {
"command": "npx",
"args": ["-y", "codex-delegate-mcp"]
}
}
}
Then ask Cursor to delegate implementation to Codex the same way.
copilot plugin install andreilungeanu/codex-delegate-mcp
.vscode/mcp.json{
"servers": {
"codex-delegate": {
"type": "stdio",
"command": "npx",
"args": ["-y", "codex-delegate-mcp"]
}
}
}
Or run Chat: Install Plugin From Source with this repository's URL.
Under Settings → Tools → AI Assistant → Model Context Protocol (MCP), add a server with command npx and arguments -y codex-delegate-mcp.
~/.codeium/windsurf/mcp_config.json{
"mcpServers": {
"codex-delegate": {
"command": "npx",
"args": ["-y", "codex-delegate-mcp"]
}
}
}
Heads-up: Cascade caps you at 100 tools across all servers.
%USERPROFILE%\.mcp.json{
"servers": {
"codex-delegate": {
"type": "stdio",
"command": "npx",
"args": ["-y", "codex-delegate-mcp"]
}
}
}
Requires 17.14+. Note the top-level key is servers, not mcpServers.
Add the following server to the client's MCP config:
{
"mcpServers": {
"codex-delegate": {
"command": "npx",
"args": ["-y", "codex-delegate-mcp"]
}
}
}
MIT © Andrei Lungeanu
Configuration · Security · Privacy · Terms · Changelog
FAQs
MCP bridge that lets Claude Code and other hosts delegate implementation to the OpenAI Codex CLI.
The npm package codex-delegate-mcp receives a total of 54 weekly downloads. As such, codex-delegate-mcp popularity was classified as not popular.
We found that codex-delegate-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.