Atlas / MCP servers / leonardsellem / Codex Specialized Subagents

Codex Specialized SubagentsSAFE

mcp/leonardsellem/codex-specialized-subagents

MCP server that lets Codex delegate to isolated codex exec sub-agents, selecting repo+global skills automatically

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
5 4r · 1w · 0d
Transport
stdio
License
MIT
Stars
69
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Artifact-first sub-agent delegation for Codex CLI (MCP server).

This repo provides a local (stdio) MCP server that exposes:

  • delegate_autopilot — decide whether to delegate and, if yes, orchestrate one or more codex exec sub-agent runs
  • delegate_run — run a single specialist sub-agent via codex exec
  • delegate_resume — resume a prior sub-agent thread via codex exec resume

Each tool call writes a run directory under ${CODEX_HOME:-$HOME/.codex}/delegator/runs// containing the prompt, selected skills, event stream, and structured results (artifact-first debugging).

When to use

  • You want parallelism and specialization for multi-step / cross-cutting work.
  • You want durable artifacts (logs + outputs) to debug and review what happened.

Requirements

  • Node.js >=20 (see package.json#engines)
  • npm
  • mise (recommended): installs the pinned runtime from mise.toml
  • codex CLI on your PATH and authenticated (required for real delegation runs)

Optional:

  • Python 3 (only for helper scripts under .agent/)

Install & quickstart (from source)

From the repo root (installs deps + builds dist/):

# Recommended: install the pinned runtime (see mise.toml)
mise install

# Drift check (lockfiles + pins)
./toolchain-check.sh

# Install deps from lockfile
npm ci

# Build
npm run build

Configure Codex (recommended, prevents timeouts)

Delegated runs can take minutes. Set this server’s MCP tool timeout to 1200 seconds (20 minutes) in your Codex config ($HOME/.codex/config.toml):

mkdir -p "$HOME/.codex"
cat >> "$HOME/.codex/config.toml" <<'EOF'

[mcp_servers.codex-specialized-subagents]
tool_timeout_sec = 1200
EOF

If you already have a [mcp_servers.codex-specialized-subagents] section, edit the existing tool_timeout_sec instead of appending a duplicate.

Common gotcha: tool_timeout_sec is not an env var. If you put it under `mcp_servers.codex-specialized-subagents.

Read from source at commit 187558360596OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add codex-specialized-subagents -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "codex-specialized-subagents": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (5)

4 read · 1 write · 0 destructive.

ToolRiskDescription
api-clientreadUse when working with HTTP clients
delegate_autopilotread
delegate_resumeread
delegate_runwrite
testing-helperreadGreat for api client work
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tests/codex/configOverrides.test.ts:4
import { buildCodexConfigOverrides, buildDelegateCodexConfigOverrides } from "../../lib/codex/configOverrides.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tests/delegation/autopilot-models.test.ts:7
import { runAutopilot } from "../../lib/delegation/autopilot.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tests/delegation/autopilot.test.ts:7
import { runAutopilot } from "../../lib/delegation/autopilot.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tests/delegation/route.test.ts:4
import { routeAutopilotTask } from "../../lib/delegation/route.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tests/delegation/runJobs.test.ts:4
import { runJobs } from "../../lib/delegation/runJobs.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod, @types/node, tsx, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 187558360596full audit observations/trust-audit/mcp-server/leonardsellem__codex-specialized-subagents.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07187558360596SAFEB89first audit
06

Questions

What is the Codex Specialized Subagents MCP server?

MCP server that lets Codex delegate to isolated codex exec sub-agents, selecting repo+global skills automatically

What tools does Codex Specialized Subagents expose?

5 in total: 4 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Codex Specialized Subagents safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Codex Specialized Subagents need?

No credential environment variables were found in its source, so it appears to need none.

How does Codex Specialized Subagents run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as codex-specialized-subagents at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (187558360596), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement