AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Ds Delegate

skill-rbinar-cli-dispatch-ds-delegate · by rbinar

|

No reviews yet
0 installs
29 views
0.0% view→install

Install

$ agentstack add skill-rbinar-cli-dispatch-ds-delegate

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-rbinar-cli-dispatch-ds-delegate)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Ds Delegate? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

claude-ds — DeepSeek delegation worker

claude-ds is a portable wrapper installed to ~/.local/bin by /cli-dispatch:setup; it runs the Claude Code CLI against DeepSeek's Anthropic-compatible API. Since it's on PATH, call it directly as claude-ds (no old zsh -ic function trick needed).

When / when not

  • The built-in Agent/subagent tool does NOT support DeepSeek (model enum: sonnet/opus/haiku/fable).

This is the only way to hand work to DeepSeek.

  • Conversation context is not shared → the prompt must be self-contained.

Wrappers

  • ds-agent (SIMPLEST — subagent-style) — one synchronous command: give it a task, it

runs to completion, streams tool activity to stderr, and prints only the final answer to stdout. Default agentic (may write/run in --cwd); --read-only for analysis-only. Best when you just want "delegate this and give me the result" in a single call.

  • claude-ds-stream — runs claude with stream-json, parses output into a **session

directory** (live + observable + resumable). Use when you want to run in the background and poll, or need the session id / --resume / /cli-dispatch:watch workflow.

  • claude-ds — plain env wrapper (claude "$@"). No parsing/session; fast one-shot only.

ds-agent — single command (subagent-style)

ds-agent ""                     # agentic in cwd; live progress on stderr; answer on stdout
ds-agent --read-only ""     # no writes / no bash
ds-agent --cwd  ""         # work in  (use an isolated dir for safety)
ds-agent --resume  ""  # continue a session
echo "" | ds-agent              # task via stdin

stdout = final answer only (safe to capture/pipe); stderr = banner + live tool activity. Exit code is the worker's. -q silences the banner/progress. It forwards --max-runtime/--idle-timeout to the underlying claude-ds-stream.

Session directory: ${XDG_CACHE_HOME:-$HOME/.cache}/cli-dispatch/sessions// (legacy claude-ds path still read as a fallback)

  • status.json — compact rolling summary (the only file to poll: state, lastTool, toolCounts, finalResultPreview)
  • progress.log — terse human-readable stream (▸ Edit foo.ts, ✓/✗, truncated text)
  • transcript.jsonl — raw stream-json (resume/audit; NOT read while polling)
  • meta.json — prompt preview, cwd, branch, model, start/end

Offloading to the ds-runner subagent (keep your context clean)

Instead of running the ds-* CLIs yourself and babysitting them, you can hand the whole delegation to the bundled ds-runner subagent. It runs/monitors/isolates/verifies the DeepSeek work in its own context and returns a short result — the management churn never enters yours. Pick its model by difficulty (the worker stays DeepSeek either way):

Agent(subagent_type="ds-runner", model="haiku",  prompt="")  # pure gen/analysis (default)
Agent(subagent_type="ds-runner", model="sonnet", prompt="")  # needs build/test verification

Worth it for long/agentic tasks, verification, or running several in parallel. For a quick one-shot, just call ds-agent directly (the subagent's extra model layer isn't worth it).

Run rules

  • Always run as a background task: Bash tool run_in_background: true (don't block).
  • For a long prompt, write the brief to a file and pass it with -p "$(cat )".
  • Cost-conscious monitoring (MANDATORY): track progress by reading only the small status.json

(/cli-dispatch:watch ). Don't read the raw transcript.jsonl; don't tail it repeatedly in a tight loop; check once per orchestration step. When the task finishes you get re-invoked anyway.

  • Windows: after setup, claude-ds / claude-ds-stream are called directly (.cmd shim);

the parser .mjs is shared cross-platform. On macOS/Linux/WSL the .sh variants apply.

> Not a sandbox by default. The wrapper always runs with --permission-mode > bypassPermissions (the CLI can't prompt in non-interactive --print mode), so the > worker can write files and run bash even without --dangerously-skip-permissions. > "Generation mode" is a convention (you didn't give it a file task), not an enforced > sandbox. For real-repo tasks, isolate in a worktree. For guaranteed no-writes, use --read-only.

Mode 1 — Generation (code/text/analysis)

claude-ds-stream -p ""

The final text goes to stdout, progress goes to the session directory. Session id on stderr. The worker can still write files if the prompt leads it to — add --read-only to forbid that.

Mode 1-safe — True read-only (denies Write/Edit/Bash; nothing mutated)

claude-ds-stream --read-only -p ""

Use when the output must be text-only and the worker must not touch disk.

Mode 2 — Full agentic (writes files + runs bash)

claude-ds-stream --cwd  --dangerously-skip-permissions -p "$(cat /tmp/ds-brief.txt)"

Writes files / runs bash → you MUST isolate it (worktree). (--dangerously-skip-permissions is largely redundant with the default bypassPermissions; it signals intent and matches the worktree helper.)

Follow-up / resume (continue the same DeepSeek session)

claude-ds-stream --resume  -p ""

The transcript is appended to the same session; status.json is updated. See sessions: /cli-dispatch:sessions.

Timeouts (safety net for hung/runaway workers)

claude-ds-stream --max-runtime 600 --idle-timeout 90 -p ""   # seconds; 0 = off (default)

A background watchdog kills the worker (and its child processes) if it exceeds the overall runtime cap (--max-runtime) or stalls with no new output (--idle-timeout, measured from transcript.jsonl activity). Timed-out sessions are marked state: error with error: "timeout: …". Env fallbacks: CLAUDE_DS_MAX_RUNTIME, CLAUDE_DS_IDLE_TIMEOUT. Both default off. Enforced on both wrappers — bash via a kill_tree watchdog, PowerShell via a background-job watchdog that locates the worker by its session id and kills the tree with taskkill /T /F.

Safe operation for a real repo task (MANDATORY)

Use the bundled helper:

"${CLAUDE_PLUGIN_ROOT}/scripts/ds-worktree-run.sh"   

This script: opens an isolated git worktree (origin/main), symlinks node_modules if present, runs claude-ds-stream in Mode 2 inside the worktree (session-tracked), and leaves the diff UNCOMMITTED. The session id is printed on stderr → watch it with /cli-dispatch:watch .

Then YOU are the reviewer:

  1. Review the FULL diff with git -C status && git -C diff — check for

side effects, confirm only the target files were touched.

  1. Run tsc/build/test yourself (independent verification).
  2. If all good, YOU do the git: commit → push → PR → merge → git pull origin main on the main checkout.

Note in the commit body that "implementation was delegated to claude-ds (DeepSeek)" (transparency).

  1. Cleanup: rm /node_modulesgit worktree remove --forcegit worktree prune.

Antigravity (Gemini) backend — ag-agent / ag-stream

cli-dispatch's second worker is Antigravity (agy, Google's Gemini-powered agentic CLI). It's a different binary from claude with its own auth/config — the DeepSeek "swap the env var" trick does NOT apply. Enable it via /cli-dispatch:setup (choose Antigravity/Both).

The ag-* family mirrors the ds-* one, so the workflow is the same — only the command name changes:

ag-agent ""                     # agentic in cwd; live progress on stderr; answer on stdout
ag-agent -q ""                  # answer only on stdout (banner/progress silenced)
ag-agent --cwd  ""         # work in ;  is registered as agy's workspace
ag-agent --resume  ""   # continue the same agy conversation
ag-agent --model "Claude Opus 4.6 (Thinking)" ""   # pick a specific model (see below)
ag-stream --cwd  -p ""     # background/session-tracked variant (poll status.json)
  • Model selection (agy proxies multiple families): agy models lists them; pass the EXACT

display name to --model (config default: AG_MODEL). Verified working cross-vendor — e.g. --model "Claude Opus 4.6 (Thinking)" actually routes to Claude, "Gemini 3.1 Pro (High)" to Gemini. Current list: Gemini 3.5 Flash (Low|Medium|High), Gemini 3.1 Pro (Low|High), Claude Sonnet 4.6 (Thinking), Claude Opus 4.6 (Thinking), GPT-OSS 120B (Medium). Default Gemini 3.5 Flash (High). ⚠ An unknown name makes agy SILENTLY use its default — ag-stream warns when --model isn't in agy models, but double-check the exact string (incl. suffix).

  • Same session dir as DeepSeek (…/cli-dispatch/sessions// with status.json etc.), so

/cli-dispatch:sessions / watch work for both. The session id IS the agy conv-id.

  • How it works: agy has no --output-format json and a non-TTY silent-drop bug, so

ag-stream runs it under a pseudo-TTY (script) and tails agy's on-disk JSONL transcript for live progress + the final answer. Requires script (pseudo-tty) + node.

  • Auth: Google sign-in (run agy once) or GEMINI_API_KEY/ANTIGRAVITY_API_KEY in the config.
  • no read-only mode: agy has no tool-level write-deny (--sandbox restricts the terminal,

not file writes — tested), so --read-only is rejected. For a no-writes guarantee, isolate in a throwaway/worktree --cwd and review the diff.

  • timeout semantics differ from DeepSeek: agy spawns detached workers + runs under a pty,

so an external tree-kill is unreliable (verified: SIGKILL on the tracked tree left agy working). --max-runtime N is therefore enforced via agy's OWN --print-timeout (a per-model-wait cap, so total wall-time may exceed N), and the watchdog is only a best-effort backstop for a fully-hung agy. A capped run may report done (partial output) or error (no final answer), not a guaranteed error. For a true wall-clock bound, run it yourself under timeout(1)/worktree and don't rely on the worker self-terminating.

  • Isolation: same worktree rule for real-repo tasks — run ag-agent --cwd and

review the diff yourself. (Worktree isolation also avoids agy's per-workspace conv-id race.)

  • Babysitter subagent: the ag-runner subagent manages an Antigravity delegation in a

sub-context (or call ag-agent directly in a worktree and verify the result yourself).

Codex (OpenAI) backend — cx-agent / cx-stream

cli-dispatch's third worker is Codex (codex, OpenAI's Codex CLI ≥ 0.142.3) — again a different binary with its own auth. Enable it via /cli-dispatch:setup (choose Codex).

The cx-* family mirrors the ds-* one:

cx-agent ""                       # agentic in cwd; live progress on stderr; answer on stdout
cx-agent -q ""                    # answer only on stdout
cx-agent --read-only -q ""    # REAL OS-level read-only sandbox (no writes / no bash)
cx-agent --cwd  ""           # work in 
cx-agent --model gpt-5.4-mini ""  # pick a model (see below)
cx-agent --resume  ""   # continue the same codex thread (do NOT pass --cwd)
cx-stream --cwd  -p ""       # background/session-tracked variant (poll status.json)
  • Real OS-level read-only sandbox (headline feature): cx-agent --read-only passes

-s read-only to codex → macOS Seatbelt / Linux bwrap+seccomp, a kernel-enforced hard-block on all file writes. Unlike DeepSeek (tool-layer restriction) and Antigravity (none), this is a genuine no-writes guarantee — no worktree needed for pure analysis. Sandbox defaults to workspace-write for agentic work; override with --sandbox read-only|workspace-write|danger-full-access.

  • Model selection: --model (config default CX_MODEL; blank = codex's own default).

Current: gpt-5.5 (default, frontier), gpt-5.4 (flagship), gpt-5.4-mini (fast/cheap, subagents), gpt-5.3-codex-spark (ChatGPT Pro preview). gpt-5.2/gpt-5.3-codex deprecated. Run /model inside codex for the live list.

  • Same session dir as the others (…/cli-dispatch/sessions//), so /cli-dispatch:sessions

/ watch work for all three. The session id is the codex thread-id.

  • How it works: codex exec --json emits a clean JSONL stream → cx-stream pipes it

through cx-stream-parse.mjs (no pseudo-TTY/file-tail needed). Requires node.

  • Auth: codex login (ChatGPT/OAuth — no key for personal use) or CODEX_API_KEY

(takes precedence over OPENAI_API_KEY).

  • Babysitter subagent: the cx-runner subagent manages a Codex delegation in a sub-context.

OpenCode (via OpenRouter) backend — oc-agent / oc-stream

cli-dispatch's fourth worker is OpenCode (opencode, npm opencode-ai), driven through OpenRouter so any OpenRouter model slug works. Enable it via /cli-dispatch:setup (choose OpenCode). Unix-only (macOS/Linux/WSL).

The oc-* family mirrors the others:

oc-agent ""                          # agentic in cwd; progress on stderr; answer on stdout
oc-agent -q ""                       # answer only on stdout
oc-agent --cwd  ""              # work in 
oc-agent --model google/gemma-4-31b-it:free ""   # bare OpenRouter slug (oc-stream adds openrouter/)
oc-agent --resume  ""           # continue the same session (verified: targets the NAMED session)
oc-stream --cwd  -p ""          # background/session-tracked variant (poll status.json)
  • NO sandbox at all — no OS-level or tool-level write-deny; --auto (always passed) is a

functional headless requirement, not a safety opt-in. Git-worktree isolation is the only safety boundary (same posture as Antigravity).

  • Model selection: --model (config default OC_MODEL). Invalid slugs fail

loudly with an OpenRouter API error. Live list: OPENROUTER_API_KEY= opencode models openrouter.

  • Auth: OPENROUTER_API_KEY in the config (pasted by the user — never written by Claude).
  • Same session dir as the others, so sessions / watch / resume / kill all work.
  • Babysitter subagent: the oc-runner subagent manages an OpenCode delegation in a sub-context.

GitHub Copilot backend — cp-agent / cp-stream

cli-dispatch's fifth worker is GitHub Copilot (copilot, npm @github/copilot). Enable it via /cli-dispatch:setup (choose GitHub Copilot). Unix-only (macOS/Linux/WSL).

The cp-* family mirrors the OpenCode backend:

cp-agent ""                          # agentic in cwd; progress on stderr; answer on stdout
cp-agent -q ""                       # answer only on stdout
cp-agent --cwd  ""              # work in ; passed to copilot as --add-dir
cp-agent --model gpt-5.4 ""          # Copilot model slug (e.g. gpt-5.4, auto)
cp-agent --effort high ""            # maps to --reasoning-effort=high
cp-agent --resume  ""           # continue the same session
cp-stream --cwd  -p ""          # background/session-tracked variant (poll status.json)
  • NO sandbox at all — no OS-level or tool-level write-deny; `--allow-all-tools

--no-ask-user` is always passed for headless use, not as a safety opt-in. Git-worktree isolation is the only safety boundary (same posture as OpenCode and Antigravity).

  • Model selection: --model (config default CP_MODEL). Examples:

gpt-5.4, auto. Current model list is only visible interactively via /model in the copilot TUI (auth required) or GitHub Copilot docs — slugs change over time.

  • Reasoning effort: --effort low|medium|high maps to Copilot's

--reasoning-effort=.

  • Auth: COPILOT_GITHUB_TOKEN > GH_TOKEN > GITHUB_TOKEN; cli-dispatch automatically

reuses gh auth token as GH_TOKEN when available. An active GitHub Copilot subscription is required.

  • Balance: not queryable from the CLI. /usage is interactive-only inside a Copilot REPL;

use https://github.com/settings/billing for real usage/limits.

  • Same session dir as the others, so sessions / watch / resume / kill all work.
  • Babysitter subagent: the cp-runner subagent manages a Copilot delega

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

  • Author: rbinar
  • Source: rbinar/cli-dispatch
  • License: MIT
  • Homepage: https://medium.com/@rbinar/cli-dispatch-claudea-patron-deepseek-e-i%CC%87%C5%9F%C3%A7i-rol%C3%BC-veren-bir-plugin-b232803581fc

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.