Claude DelegatorSAFE
MCP server: delegate heavy-token tasks from Claude Code to DeepSeek, Kimi, GLM, Qwen, Grok, or any OpenAI-compatible model. Mix providers per task, cost receipt on every call. Zero dependencies.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
### 🚀 3.0 is out — now model-agnostic One tool, any model: DeepSeek, Kimi, GLM, Qwen, Grok, Groq, OpenRouter, even your local ollama — and you can mix them per task. Plus a rebuilt interactive installer, a model picker inside Claude Code, and a receipt for every cent. v2 installs keep working untouched. See what's new ↓
Cut your Claude Code bill by 90–97% on heavy work — big file audits, long generations, deep reasoning — by delegating it to a cheaper model without leaving your session.
Claude orchestrates; the delegate does the grunt work (big file audits, long generations, deep reasoning) at a fraction of the price. One tool call, no subagent spawn, no daemon, zero dependencies.
One command installs everything. init is an interactive wizard that wires up the delegate tool, the automatic gate (the "Delegate to DeepSeek? (y/n)" nudge before heavy reads and skill loads), your provider + API key (live-validated), and how models get picked. Run it once, restart Claude Code, and delegation just happens.
⭐ If this saves you money, please [star the repo](https://github.com/fjgbue/claude-delegator-deepseek-mcp). It's the single biggest thing that helps other Claude Code users find it.
b3426835af1dOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add claude-code-deepseek-delegator --env DEEPSEEK_API_KEY=${DEEPSEEK_API_KEY} --env MOONSHOT_API_KEY=${MOONSHOT_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"claude-code-deepseek-delegator": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"DEEPSEEK_API_KEY": "${DEEPSEEK_API_KEY}",
"MOONSHOT_API_KEY": "${MOONSHOT_API_KEY}"
}
}
}
}Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
deepseek | read | Alias of delegate (kept for v2 compatibility). |
deepseek_models | read | Alias of delegate_models (kept for v2 compatibility). |
delegate_models | read | List the configured providers and their models with context windows, output limits, and pricing |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- declared (5 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
const VERSION = createRequire(import.meta.url)('../../package.json').version;api_endpoint: `http://127.0.0.1:${server.address().port}/v1`,api_key: 'sk-mock', api_endpoint: `http://127.0.0.1:${port}/v1`,Gates applied: no_behavioural_pass.
b3426835af1dfull audit observations/trust-audit/mcp-server/12122j__claude-delegator-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b3426835af1d | SAFE | B | 89 | first audit |
Questions
What is the Claude Delegator MCP server?
MCP server: delegate heavy-token tasks from Claude Code to DeepSeek, Kimi, GLM, Qwen, Grok, or any OpenAI-compatible model. Mix providers per task, cost receipt on every call. Zero dependencies.
What tools does Claude Delegator expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Claude Delegator safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Claude Delegator need?
It reads DEEPSEEK_API_KEY and MOONSHOT_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (b3426835af1d), read on 2026-10-07. The repository is watched and re-audited when it changes.