
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
codex-delegate-mcp
Advanced tools
MCP bridge that lets Claude Code and other hosts delegate implementation to the OpenAI Codex CLI.
Stop burning your frontier agent's limits on boilerplate.
Delegate implementation to the OpenAI Codex CLI — your agent writes the brief and reviews the diff.
Use your best coding agent where its judgment matters most: understanding the task, shaping the plan, and reviewing the result.
Codex Delegate is the MCP bridge that lets Claude Code, Cursor, Copilot — or any MCP client — hand implementation to the OpenAI Codex CLI, then get a clean, structured result back for review.

Your assistant does what frontier models are actually for: understands the task, writes a precise brief, reviews the finished diff. Codex holds its own as the implementer — guided and checked by a smarter orchestrator. The result reads like frontier work, because a frontier model planned it and signed off on it.
Codex tears through multi-file edits while a frontier chat model would still be streaming the first file. You delegate, keep working with your assistant, and the diff shows up done.
Delegated work runs on the OpenAI Codex CLI and its own usage — separate from your orchestrator's chat quota, though the Codex side still bills its own way. Your Claude, Cursor, or Copilot subscription spends tokens on the brief and the review; Codex does the grinding. On API? That's the per-token grind moved off your main bill.


status, the files Codex's edit tools reported changing, per-turn token counts, and the threadId to continue from. Fields that carry no signal are omitted.plan returns schema-validated steps for you to approve, and agent implements them. ask answers questions. review runs Codex's own reviewer over uncommitted work, a base branch, or a single commit.resumeThreadId. resumed: false tells you the context did not carry over.cancel waits for the exit and warns when a process outlives the kill deadline.doctor — tells you exactly what's missing if setup isn't right.You need Node.js 20+ and the OpenAI Codex CLI, already logged in (codex login).
/plugin marketplace add andreilungeanu/codex-delegate-mcp
/plugin install codex-delegate@codex-delegate-mcp
Then just ask:
Delegate to Codex: migrate src/api from callbacks to async/await and update the tests, then walk me through what changed.
That's the whole loop — Claude writes the brief, Codex grinds through the files, Claude walks you through the diff.
Add an MCP server in Cursor Settings → MCP (or project .cursor/mcp.json):
{
"mcpServers": {
"codex-delegate": {
"command": "npx",
"args": ["-y", "codex-delegate-mcp"]
}
}
}
Then ask Cursor to delegate implementation to Codex the same way.
copilot plugin install andreilungeanu/codex-delegate-mcp
.vscode/mcp.json{
"servers": {
"codex-delegate": {
"type": "stdio",
"command": "npx",
"args": ["-y", "codex-delegate-mcp"]
}
}
}
Or run Chat: Install Plugin From Source with this repository's URL.
Under Settings → Tools → AI Assistant → Model Context Protocol (MCP), add a server with command npx and arguments -y codex-delegate-mcp.
~/.codeium/windsurf/mcp_config.json{
"mcpServers": {
"codex-delegate": {
"command": "npx",
"args": ["-y", "codex-delegate-mcp"]
}
}
}
Heads-up: Cascade caps you at 100 tools across all servers.
%USERPROFILE%\.mcp.json{
"servers": {
"codex-delegate": {
"type": "stdio",
"command": "npx",
"args": ["-y", "codex-delegate-mcp"]
}
}
}
Requires 17.14+. Note the top-level key is servers, not mcpServers.
Add the following server to the client's MCP config:
{
"mcpServers": {
"codex-delegate": {
"command": "npx",
"args": ["-y", "codex-delegate-mcp"]
}
}
}
MIT © Andrei Lungeanu
Configuration · Security · Privacy · Terms · Changelog
FAQs
MCP bridge that lets Claude Code and other hosts delegate implementation to the OpenAI Codex CLI.
The npm package codex-delegate-mcp receives a total of 40 weekly downloads. As such, codex-delegate-mcp popularity was classified as not popular.
We found that codex-delegate-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.