Install
$ agentstack add mcp-alex-kaff-claude-wrap-mcp ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
claude-wrap-mcp
[](https://www.npmjs.com/package/claude-wrap-mcp) [](./LICENSE) [](https://nodejs.org)
An MCP server that lets any MCP-capable agent (Claude Code, Claude Desktop, Cursor, …) spawn and drive Claude Code sessions — effectively turning Claude Code into an orchestratable sub-agent fleet. Built on the claude-wrap library.
Requirements
- Node ≥ 18
- The
claudeCLI on yourPATH(the sessions run real Claude Code). claude-wrappulls the nativenode-pty
addon, so a prebuilt binary or a C/C++ toolchain is needed at install time.
- Spawning headless sessions works cross-platform; **attaching to visible
windows is Windows-first**.
Install & register
npm install -g claude-wrap-mcp
# then, in Claude Code:
claude mcp add claude-wrap -- claude-wrap-mcp
Or via JSON config (.mcp.json / claude_desktop_config.json):
{
"mcpServers": {
"claude-wrap": { "command": "npx", "args": ["-y", "claude-wrap-mcp"] }
}
}
Once published, it's also discoverable in the MCP Registry as io.github.Alex-Kaff/claude-wrap-mcp.
Tools
| Tool | What it does | |---|---| | claude_spawn | Start a headless session in an absolute cwd. Returns a sessionId. | | claude_ask | Send a prompt, wait for idle, return transcript tail + parsed state. Returns status:"busy" on timeout (not an error). | | claude_send | Send raw input (text / line / key) without waiting — for long tasks; then poll. | | claude_status | Parsed state: busy, mode, tokens, pending permission prompt, todos, tool calls. | | claude_snapshot | The rendered transcript lines. | | claude_list | All sessions — in-process (spawned here) and external (discovered windows). | | claude_resolve_permission | approve / deny a pending permission prompt. | | claude_stop | Shut down an in-process session. |
Permission prompts are surfaced, not auto-bypassed: when claude_ask / claude_status report a pending permissionPrompt, resolve it with claude_resolve_permission.
Control models
- In-process (primary): the server owns a
claude-wrapClaudeManagerand
drives headless sessions directly — full parsed state and lifecycle.
- External (Windows-first): sessions launched elsewhere (visible windows)
are discovered via the registry and driven over their pipe; parsed operations are delegated to the claude-wrap-inject bin. Best-effort; claude_stop is declined for instances this server did not spawn.
Develop
pnpm install
pnpm --filter claude-wrap-mcp build # tsup -> dist/ (ESM + .d.ts, shebang on the bin)
pnpm --filter claude-wrap-mcp test # vitest, in-memory MCP client against fakes
pnpm --filter claude-wrap-mcp inspect # @modelcontextprotocol/inspector on the built server
License
[MIT](./LICENSE) © Alex Kaffetzakis
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Alex-Kaff
- Source: Alex-Kaff/claude-wrap-mcp
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.