Codex Specialized SubagentsSAFE
MCP server that lets Codex delegate to isolated codex exec sub-agents, selecting repo+global skills automatically
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Artifact-first sub-agent delegation for Codex CLI (MCP server).
This repo provides a local (stdio) MCP server that exposes:
delegate_autopilot— decide whether to delegate and, if yes, orchestrate one or morecodex execsub-agent runsdelegate_run— run a single specialist sub-agent viacodex execdelegate_resume— resume a prior sub-agent thread viacodex exec resume
Each tool call writes a run directory under ${CODEX_HOME:-$HOME/.codex}/delegator/runs// containing the prompt, selected skills, event stream, and structured results (artifact-first debugging).
When to use
- You want parallelism and specialization for multi-step / cross-cutting work.
- You want durable artifacts (logs + outputs) to debug and review what happened.
Requirements
- Node.js
>=20(seepackage.json#engines) npmmise(recommended): installs the pinned runtime frommise.tomlcodexCLI on your PATH and authenticated (required for real delegation runs)
Optional:
- Python 3 (only for helper scripts under
.agent/)
Install & quickstart (from source)
From the repo root (installs deps + builds dist/):
# Recommended: install the pinned runtime (see mise.toml) mise install # Drift check (lockfiles + pins) ./toolchain-check.sh # Install deps from lockfile npm ci # Build npm run build
Configure Codex (recommended, prevents timeouts)
Delegated runs can take minutes. Set this server’s MCP tool timeout to 1200 seconds (20 minutes) in your Codex config ($HOME/.codex/config.toml):
mkdir -p "$HOME/.codex" cat >> "$HOME/.codex/config.toml" <<'EOF' [mcp_servers.codex-specialized-subagents] tool_timeout_sec = 1200 EOF
If you already have a [mcp_servers.codex-specialized-subagents] section, edit the existing tool_timeout_sec instead of appending a duplicate.
Common gotcha: tool_timeout_sec is not an env var. If you put it under `mcp_servers.codex-specialized-subagents.
187558360596OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add codex-specialized-subagents -- npx -y [email protected]
{
"mcpServers": {
"codex-specialized-subagents": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (5)
4 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
api-client | read | Use when working with HTTP clients |
delegate_autopilot | read | |
delegate_resume | read | |
delegate_run | write | |
testing-helper | read | Great for api client work |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
import { buildCodexConfigOverrides, buildDelegateCodexConfigOverrides } from "../../lib/codex/configOverrides.js";import { runAutopilot } from "../../lib/delegation/autopilot.js";import { runAutopilot } from "../../lib/delegation/autopilot.js";import { routeAutopilotTask } from "../../lib/delegation/route.js";import { runJobs } from "../../lib/delegation/runJobs.js";@modelcontextprotocol/sdk, zod, @types/node, tsx, typescript
Gates applied: no_behavioural_pass.
187558360596full audit observations/trust-audit/mcp-server/leonardsellem__codex-specialized-subagents.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 187558360596 | SAFE | B | 89 | first audit |
Questions
What is the Codex Specialized Subagents MCP server?
MCP server that lets Codex delegate to isolated codex exec sub-agents, selecting repo+global skills automatically
What tools does Codex Specialized Subagents expose?
5 in total: 4 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Codex Specialized Subagents safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Codex Specialized Subagents need?
No credential environment variables were found in its source, so it appears to need none.
How does Codex Specialized Subagents run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as codex-specialized-subagents at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (187558360596), read on 2026-10-07. The repository is watched and re-audited when it changes.