Atlas / MCP servers / 12122j / Claude Delegator

Claude DelegatorSAFE

mcp/12122j/claude-delegator-1

MCP server: delegate heavy-token tasks from Claude Code to DeepSeek, Kimi, GLM, Qwen, Grok, or any OpenAI-compatible model. Mix providers per task, cost receipt on every call. Zero dependencies.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
3 3r · 0w · 0d
Transport
—
License
MIT
Stars
53
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

### 🚀 3.0 is out — now model-agnostic One tool, any model: DeepSeek, Kimi, GLM, Qwen, Grok, Groq, OpenRouter, even your local ollama — and you can mix them per task. Plus a rebuilt interactive installer, a model picker inside Claude Code, and a receipt for every cent. v2 installs keep working untouched. See what's new ↓

Cut your Claude Code bill by 90–97% on heavy work — big file audits, long generations, deep reasoning — by delegating it to a cheaper model without leaving your session.

Claude orchestrates; the delegate does the grunt work (big file audits, long generations, deep reasoning) at a fraction of the price. One tool call, no subagent spawn, no daemon, zero dependencies.

One command installs everything. init is an interactive wizard that wires up the delegate tool, the automatic gate (the "Delegate to DeepSeek? (y/n)" nudge before heavy reads and skill loads), your provider + API key (live-validated), and how models get picked. Run it once, restart Claude Code, and delegation just happens.

⭐ If this saves you money, please [star the repo](https://github.com/fjgbue/claude-delegator-deepseek-mcp). It's the single biggest thing that helps other Claude Code users find it.
Read from source at commit b3426835af1dOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add claude-code-deepseek-delegator --env DEEPSEEK_API_KEY=${DEEPSEEK_API_KEY} --env MOONSHOT_API_KEY=${MOONSHOT_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "claude-code-deepseek-delegator": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "DEEPSEEK_API_KEY": "${DEEPSEEK_API_KEY}",
        "MOONSHOT_API_KEY": "${MOONSHOT_API_KEY}"
      }
    }
  }
}
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
deepseekreadAlias of delegate (kept for v2 compatibility).
deepseek_modelsreadAlias of delegate_models (kept for v2 compatibility).
delegate_modelsreadList the configured providers and their models with context windows, output limits, and pricing
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
declared (5 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (3)

LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/setup/init.mjs:34
const VERSION = createRequire(import.meta.url)('../../package.json').version;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/chunk-boundaries.test.mjs:50
api_endpoint: `http://127.0.0.1:${server.address().port}/v1`,
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/routing-e2e.test.mjs:42
api_key: 'sk-mock', api_endpoint: `http://127.0.0.1:${port}/v1`,

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha b3426835af1dfull audit observations/trust-audit/mcp-server/12122j__claude-delegator-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07b3426835af1dSAFEB89first audit
06

Questions

What is the Claude Delegator MCP server?

MCP server: delegate heavy-token tasks from Claude Code to DeepSeek, Kimi, GLM, Qwen, Grok, or any OpenAI-compatible model. Mix providers per task, cost receipt on every call. Zero dependencies.

What tools does Claude Delegator expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Claude Delegator safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Claude Delegator need?

It reads DEEPSEEK_API_KEY and MOONSHOT_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (b3426835af1d), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement