Install
$ agentstack add skill-adityak74-my-claude-skills-multi-agent-delegator ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Multi-Agent Delegator
Core principle
Act as the lead engineer in the current Claude Code pane. Delegate bounded work to interactive Codex and Antigravity sessions in visible cmux panes; retain architecture, coordination, review, and integration.
Use the goal supplied after /multi-agent-delegator as the objective. Do not delegate when the work is tiny, tightly sequential, or safer to complete directly.
Non-negotiable rules
- Always launch delegates in a new visible cmux pane.
- Start the agent interactively with exactly
codex --yolooragy --bypass-dangerous-permissions. - Never pass the task as a CLI argument.
- Send the task through cmux to the delegate's explicit surface, then send Enter as a separate action.
- Never rely on the focused pane for cross-pane actions; always target
--surface. - Never let writable parallel delegates share a working directory when overlap is possible.
- Never authorize credentials, production changes, force-push/history rewrite, user-data deletion, or irreversible external actions unless the user explicitly approves that exact action.
- Never auto-integrate work that is untested, out of scope, conflicted, or security-sensitive.
- Leave delegate panes and worktrees open unless the user requests cleanup.
1. Inspect
Before routing:
- Read repository instructions such as
CLAUDE.md,AGENTS.md, andGEMINI.md. - Check repo root, branch, status, test commands, and whether the goal depends on uncommitted changes.
- Load an installed cmux skill when available. Its verified syntax overrides examples here.
- Verify tools rather than inventing flags:
command -v cmux codex agy
cmux ping
cmux identify --json
cmux capabilities --json
If cmux, the chosen delegate, explicit surface targeting, or screen reading is unavailable, stop and report the missing capability.
2. Route
Announce a compact plan, then proceed unless the user overrides it:
Agent Objective Mode Validation
Codex-1 Implement parser Worktree pytest tests/parser -q
Antigravity-1 Add edge-case tests Worktree pytest tests/parser -q
Main Coordinate/review/merge Current full test suite
Prefer:
| Delegate | Best fit | |---|---| | Codex | implementation, refactoring, bug repair, build/test fixes, objective acceptance criteria | | Antigravity | exploration, test authoring, documentation, independent approach, broad repository analysis | | Main agent | architecture, cross-task decisions, sensitive judgment, review, integration |
Default to at most three delegates. Duplicate a task across agents only when explicitly comparing approaches is worth the cost.
3. Isolate
Use a dedicated Git worktree when any of these is true:
- more than one writable delegate runs;
- file overlap is possible or uncertain;
- current branch is
main,master, a release branch, protected, or shared; - the task is a broad refactor;
- semantic conflict risk is material.
Create a unique branch and worktree from committed state, for example:
git worktree add -b "delegate/-" \
"$HOME/.claude/worktrees///-" HEAD
Shell-quote every generated path. A shared directory is allowed only for read-only work or one clearly disjoint writable delegate on a non-protected branch.
If the goal depends on dirty, uncommitted changes and safe isolation cannot preserve them, ask the user. Do not silently commit, stash, discard, or copy those changes.
4. Launch through cmux
For each delegate:
- Snapshot surfaces with
cmux list-panels --json --id-format refs. - Create a split with
cmux new-split rightorcmux new-split down. - List surfaces again and record the newly created
surface:N. - Send only the startup command to that surface, then Enter:
cmux send --surface "$SURFACE" -- "cd -- && exec codex --yolo"
cmux send-key --surface "$SURFACE" enter
For Antigravity, replace the startup command with:
cd -- && exec agy --bypass-dangerous-permissions
- Read the pane until the interactive prompt is visibly ready:
cmux read-screen --surface "$SURFACE" --lines 40
Retry startup once after inspecting the pane. A second failure marks the task blocked.
5. Deliver the task
Every delegate contract must state:
- objective and acceptance criteria;
- assigned working directory and branch;
- allowed scope and likely files/subsystem;
- repository instructions and constraints;
- required validation commands;
- no merge, cherry-pick, force-push, deployment, credential access, or edits outside scope;
- ask before destructive, external, production, security-sensitive, or ambiguous actions;
- commit only scoped changes after tests pass when using a worktree;
- completion format shown below.
For a short one-line contract:
cmux send --surface "$SURFACE" -- "$TASK_PROMPT"
cmux send-key --surface "$SURFACE" enter
Do not inject raw multiline text into an interactive TUI. For a longer contract, write it to a temporary file under /tmp/multi-agent-delegator//.md, then send a one-line instruction through cmux:
cmux send --surface "$SURFACE" -- "Read , execute that contract, and report using its completion format."
cmux send-key --surface "$SURFACE" enter
The delegate must end with:
DELEGATION_COMPLETE
Summary:
Files:
Tests:
Commit:
Risks:
Use DELEGATION_BLOCKED with the blocking question or failure when it cannot finish.
6. Monitor and steer
Track each worker in the main pane with states STARTING, WORKING, WAITING, BLOCKED, COMPLETE, or FAILED.
At natural checkpoints, inspect the exact surface:
cmux read-screen --surface "$SURFACE" --lines 60
Do not busy-loop. Continue main-agent work between checks. When a worker asks:
- answer routine, scope-preserving questions through
cmux send, followed by a separate Enter; - drive a TUI menu only after reading the current screen, using
cmux send-key --surface ...; - escalate architecture changes, ambiguous trade-offs, credentials, destructive actions, production access, or external side effects to the user.
A stalled or looping worker receives one concise corrective prompt. If it still makes no progress, mark it blocked; do not nudge indefinitely.
7. Review and integrate
For every completed writable task:
- Read the completion report and inspect
git status, commits, and the full diff from the task base. - Reject unrelated edits, secrets, generated junk, destructive changes, or violations of repository instructions.
- Run the delegate's validation independently when practical.
- Confirm the destination branch is clean and has no unresolved semantic conflict.
- Auto-integrate only when all checks pass. Prefer cherry-picking the reviewed delegate commit, then rerun relevant tests on the integrated branch.
- If any gate fails, leave the work isolated and report the exact issue. Resolve only trivial, well-understood conflicts; escalate semantic conflicts.
Minor local defects may be fixed directly and revalidated. Material defects go back to the same delegate or remain isolated.
8. Final report
Report:
Agent | Surface | Worktree/branch | Task | Result | Tests | Integration
Then summarize completed, blocked, and failed work; commits integrated; remaining decisions; and the panes/worktrees left open for inspection.
Red flags
Stop and correct the orchestration when you are about to:
- run
codex --yolo ""oragy --bypass-dangerous-permissions ""; - send to whichever pane happens to be focused;
- paste a multiline contract directly into the TUI;
- launch writable delegates on a protected branch or overlapping shared directory;
- treat bypass flags as authorization for risky actions;
- integrate based only on a delegate's claim that tests passed;
- close panes or remove worktrees before the user can inspect them.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: adityak74
- Source: adityak74/my-claude-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.