Install
$ agentstack add skill-rbinar-cli-dispatch-ds-delegate ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
claude-ds — DeepSeek delegation worker
claude-ds is a portable wrapper installed to ~/.local/bin by /cli-dispatch:setup; it runs the Claude Code CLI against DeepSeek's Anthropic-compatible API. Since it's on PATH, call it directly as claude-ds (no old zsh -ic function trick needed).
When / when not
- The built-in
Agent/subagent tool does NOT support DeepSeek (modelenum: sonnet/opus/haiku/fable).
This is the only way to hand work to DeepSeek.
- Conversation context is not shared → the prompt must be self-contained.
Wrappers
ds-agent(SIMPLEST — subagent-style) — one synchronous command: give it a task, it
runs to completion, streams tool activity to stderr, and prints only the final answer to stdout. Default agentic (may write/run in --cwd); --read-only for analysis-only. Best when you just want "delegate this and give me the result" in a single call.
claude-ds-stream— runsclaudewith stream-json, parses output into a **session
directory** (live + observable + resumable). Use when you want to run in the background and poll, or need the session id / --resume / /cli-dispatch:watch workflow.
claude-ds— plain env wrapper (claude "$@"). No parsing/session; fast one-shot only.
ds-agent — single command (subagent-style)
ds-agent "" # agentic in cwd; live progress on stderr; answer on stdout
ds-agent --read-only "" # no writes / no bash
ds-agent --cwd "" # work in (use an isolated dir for safety)
ds-agent --resume "" # continue a session
echo "" | ds-agent # task via stdin
stdout = final answer only (safe to capture/pipe); stderr = banner + live tool activity. Exit code is the worker's. -q silences the banner/progress. It forwards --max-runtime/--idle-timeout to the underlying claude-ds-stream.
Session directory: ${XDG_CACHE_HOME:-$HOME/.cache}/cli-dispatch/sessions// (legacy claude-ds path still read as a fallback)
status.json— compact rolling summary (the only file to poll: state, lastTool, toolCounts, finalResultPreview)progress.log— terse human-readable stream (▸ Edit foo.ts,✓/✗, truncated text)transcript.jsonl— raw stream-json (resume/audit; NOT read while polling)meta.json— prompt preview, cwd, branch, model, start/end
Offloading to the ds-runner subagent (keep your context clean)
Instead of running the ds-* CLIs yourself and babysitting them, you can hand the whole delegation to the bundled ds-runner subagent. It runs/monitors/isolates/verifies the DeepSeek work in its own context and returns a short result — the management churn never enters yours. Pick its model by difficulty (the worker stays DeepSeek either way):
Agent(subagent_type="ds-runner", model="haiku", prompt="") # pure gen/analysis (default)
Agent(subagent_type="ds-runner", model="sonnet", prompt="") # needs build/test verification
Worth it for long/agentic tasks, verification, or running several in parallel. For a quick one-shot, just call ds-agent directly (the subagent's extra model layer isn't worth it).
Run rules
- Always run as a background task: Bash tool
run_in_background: true(don't block). - For a long prompt, write the brief to a file and pass it with
-p "$(cat )". - Cost-conscious monitoring (MANDATORY): track progress by reading only the small
status.json
(/cli-dispatch:watch ). Don't read the raw transcript.jsonl; don't tail it repeatedly in a tight loop; check once per orchestration step. When the task finishes you get re-invoked anyway.
- Windows: after setup,
claude-ds/claude-ds-streamare called directly (.cmdshim);
the parser .mjs is shared cross-platform. On macOS/Linux/WSL the .sh variants apply.
> Not a sandbox by default. The wrapper always runs with --permission-mode > bypassPermissions (the CLI can't prompt in non-interactive --print mode), so the > worker can write files and run bash even without --dangerously-skip-permissions. > "Generation mode" is a convention (you didn't give it a file task), not an enforced > sandbox. For real-repo tasks, isolate in a worktree. For guaranteed no-writes, use --read-only.
Mode 1 — Generation (code/text/analysis)
claude-ds-stream -p ""
The final text goes to stdout, progress goes to the session directory. Session id on stderr. The worker can still write files if the prompt leads it to — add --read-only to forbid that.
Mode 1-safe — True read-only (denies Write/Edit/Bash; nothing mutated)
claude-ds-stream --read-only -p ""
Use when the output must be text-only and the worker must not touch disk.
Mode 2 — Full agentic (writes files + runs bash)
claude-ds-stream --cwd --dangerously-skip-permissions -p "$(cat /tmp/ds-brief.txt)"
Writes files / runs bash → you MUST isolate it (worktree). (--dangerously-skip-permissions is largely redundant with the default bypassPermissions; it signals intent and matches the worktree helper.)
Follow-up / resume (continue the same DeepSeek session)
claude-ds-stream --resume -p ""
The transcript is appended to the same session; status.json is updated. See sessions: /cli-dispatch:sessions.
Timeouts (safety net for hung/runaway workers)
claude-ds-stream --max-runtime 600 --idle-timeout 90 -p "" # seconds; 0 = off (default)
A background watchdog kills the worker (and its child processes) if it exceeds the overall runtime cap (--max-runtime) or stalls with no new output (--idle-timeout, measured from transcript.jsonl activity). Timed-out sessions are marked state: error with error: "timeout: …". Env fallbacks: CLAUDE_DS_MAX_RUNTIME, CLAUDE_DS_IDLE_TIMEOUT. Both default off. Enforced on both wrappers — bash via a kill_tree watchdog, PowerShell via a background-job watchdog that locates the worker by its session id and kills the tree with taskkill /T /F.
Safe operation for a real repo task (MANDATORY)
Use the bundled helper:
"${CLAUDE_PLUGIN_ROOT}/scripts/ds-worktree-run.sh"
This script: opens an isolated git worktree (origin/main), symlinks node_modules if present, runs claude-ds-stream in Mode 2 inside the worktree (session-tracked), and leaves the diff UNCOMMITTED. The session id is printed on stderr → watch it with /cli-dispatch:watch .
Then YOU are the reviewer:
- Review the FULL diff with
git -C status && git -C diff— check for
side effects, confirm only the target files were touched.
- Run tsc/build/test yourself (independent verification).
- If all good, YOU do the git: commit → push → PR → merge →
git pull origin mainon the main checkout.
Note in the commit body that "implementation was delegated to claude-ds (DeepSeek)" (transparency).
- Cleanup:
rm /node_modules→git worktree remove --force→git worktree prune.
Antigravity (Gemini) backend — ag-agent / ag-stream
cli-dispatch's second worker is Antigravity (agy, Google's Gemini-powered agentic CLI). It's a different binary from claude with its own auth/config — the DeepSeek "swap the env var" trick does NOT apply. Enable it via /cli-dispatch:setup (choose Antigravity/Both).
The ag-* family mirrors the ds-* one, so the workflow is the same — only the command name changes:
ag-agent "" # agentic in cwd; live progress on stderr; answer on stdout
ag-agent -q "" # answer only on stdout (banner/progress silenced)
ag-agent --cwd "" # work in ; is registered as agy's workspace
ag-agent --resume "" # continue the same agy conversation
ag-agent --model "Claude Opus 4.6 (Thinking)" "" # pick a specific model (see below)
ag-stream --cwd -p "" # background/session-tracked variant (poll status.json)
- Model selection (agy proxies multiple families):
agy modelslists them; pass the EXACT
display name to --model (config default: AG_MODEL). Verified working cross-vendor — e.g. --model "Claude Opus 4.6 (Thinking)" actually routes to Claude, "Gemini 3.1 Pro (High)" to Gemini. Current list: Gemini 3.5 Flash (Low|Medium|High), Gemini 3.1 Pro (Low|High), Claude Sonnet 4.6 (Thinking), Claude Opus 4.6 (Thinking), GPT-OSS 120B (Medium). Default Gemini 3.5 Flash (High). ⚠ An unknown name makes agy SILENTLY use its default — ag-stream warns when --model isn't in agy models, but double-check the exact string (incl. suffix).
- Same session dir as DeepSeek (
…/cli-dispatch/sessions//withstatus.jsonetc.), so
/cli-dispatch:sessions / watch work for both. The session id IS the agy conv-id.
- How it works: agy has no
--output-format jsonand a non-TTY silent-drop bug, so
ag-stream runs it under a pseudo-TTY (script) and tails agy's on-disk JSONL transcript for live progress + the final answer. Requires script (pseudo-tty) + node.
- Auth: Google sign-in (run
agyonce) orGEMINI_API_KEY/ANTIGRAVITY_API_KEYin the config. - no read-only mode: agy has no tool-level write-deny (
--sandboxrestricts the terminal,
not file writes — tested), so --read-only is rejected. For a no-writes guarantee, isolate in a throwaway/worktree --cwd and review the diff.
- timeout semantics differ from DeepSeek: agy spawns detached workers + runs under a pty,
so an external tree-kill is unreliable (verified: SIGKILL on the tracked tree left agy working). --max-runtime N is therefore enforced via agy's OWN --print-timeout (a per-model-wait cap, so total wall-time may exceed N), and the watchdog is only a best-effort backstop for a fully-hung agy. A capped run may report done (partial output) or error (no final answer), not a guaranteed error. For a true wall-clock bound, run it yourself under timeout(1)/worktree and don't rely on the worker self-terminating.
- Isolation: same worktree rule for real-repo tasks — run
ag-agent --cwdand
review the diff yourself. (Worktree isolation also avoids agy's per-workspace conv-id race.)
- Babysitter subagent: the
ag-runnersubagent manages an Antigravity delegation in a
sub-context (or call ag-agent directly in a worktree and verify the result yourself).
Codex (OpenAI) backend — cx-agent / cx-stream
cli-dispatch's third worker is Codex (codex, OpenAI's Codex CLI ≥ 0.142.3) — again a different binary with its own auth. Enable it via /cli-dispatch:setup (choose Codex).
The cx-* family mirrors the ds-* one:
cx-agent "" # agentic in cwd; live progress on stderr; answer on stdout
cx-agent -q "" # answer only on stdout
cx-agent --read-only -q "" # REAL OS-level read-only sandbox (no writes / no bash)
cx-agent --cwd "" # work in
cx-agent --model gpt-5.4-mini "" # pick a model (see below)
cx-agent --resume "" # continue the same codex thread (do NOT pass --cwd)
cx-stream --cwd -p "" # background/session-tracked variant (poll status.json)
- Real OS-level read-only sandbox (headline feature):
cx-agent --read-onlypasses
-s read-only to codex → macOS Seatbelt / Linux bwrap+seccomp, a kernel-enforced hard-block on all file writes. Unlike DeepSeek (tool-layer restriction) and Antigravity (none), this is a genuine no-writes guarantee — no worktree needed for pure analysis. Sandbox defaults to workspace-write for agentic work; override with --sandbox read-only|workspace-write|danger-full-access.
- Model selection:
--model(config defaultCX_MODEL; blank = codex's own default).
Current: gpt-5.5 (default, frontier), gpt-5.4 (flagship), gpt-5.4-mini (fast/cheap, subagents), gpt-5.3-codex-spark (ChatGPT Pro preview). gpt-5.2/gpt-5.3-codex deprecated. Run /model inside codex for the live list.
- Same session dir as the others (
…/cli-dispatch/sessions//), so/cli-dispatch:sessions
/ watch work for all three. The session id is the codex thread-id.
- How it works:
codex exec --jsonemits a clean JSONL stream →cx-streampipes it
through cx-stream-parse.mjs (no pseudo-TTY/file-tail needed). Requires node.
- Auth:
codex login(ChatGPT/OAuth — no key for personal use) orCODEX_API_KEY
(takes precedence over OPENAI_API_KEY).
- Babysitter subagent: the
cx-runnersubagent manages a Codex delegation in a sub-context.
OpenCode (via OpenRouter) backend — oc-agent / oc-stream
cli-dispatch's fourth worker is OpenCode (opencode, npm opencode-ai), driven through OpenRouter so any OpenRouter model slug works. Enable it via /cli-dispatch:setup (choose OpenCode). Unix-only (macOS/Linux/WSL).
The oc-* family mirrors the others:
oc-agent "" # agentic in cwd; progress on stderr; answer on stdout
oc-agent -q "" # answer only on stdout
oc-agent --cwd "" # work in
oc-agent --model google/gemma-4-31b-it:free "" # bare OpenRouter slug (oc-stream adds openrouter/)
oc-agent --resume "" # continue the same session (verified: targets the NAMED session)
oc-stream --cwd -p "" # background/session-tracked variant (poll status.json)
- NO sandbox at all — no OS-level or tool-level write-deny;
--auto(always passed) is a
functional headless requirement, not a safety opt-in. Git-worktree isolation is the only safety boundary (same posture as Antigravity).
- Model selection:
--model(config defaultOC_MODEL). Invalid slugs fail
loudly with an OpenRouter API error. Live list: OPENROUTER_API_KEY= opencode models openrouter.
- Auth:
OPENROUTER_API_KEYin the config (pasted by the user — never written by Claude). - Same session dir as the others, so
sessions/watch/resume/killall work. - Babysitter subagent: the
oc-runnersubagent manages an OpenCode delegation in a sub-context.
GitHub Copilot backend — cp-agent / cp-stream
cli-dispatch's fifth worker is GitHub Copilot (copilot, npm @github/copilot). Enable it via /cli-dispatch:setup (choose GitHub Copilot). Unix-only (macOS/Linux/WSL).
The cp-* family mirrors the OpenCode backend:
cp-agent "" # agentic in cwd; progress on stderr; answer on stdout
cp-agent -q "" # answer only on stdout
cp-agent --cwd "" # work in ; passed to copilot as --add-dir
cp-agent --model gpt-5.4 "" # Copilot model slug (e.g. gpt-5.4, auto)
cp-agent --effort high "" # maps to --reasoning-effort=high
cp-agent --resume "" # continue the same session
cp-stream --cwd -p "" # background/session-tracked variant (poll status.json)
- NO sandbox at all — no OS-level or tool-level write-deny; `--allow-all-tools
--no-ask-user` is always passed for headless use, not as a safety opt-in. Git-worktree isolation is the only safety boundary (same posture as OpenCode and Antigravity).
- Model selection:
--model(config defaultCP_MODEL). Examples:
gpt-5.4, auto. Current model list is only visible interactively via /model in the copilot TUI (auth required) or GitHub Copilot docs — slugs change over time.
- Reasoning effort:
--effort low|medium|highmaps to Copilot's
--reasoning-effort=.
- Auth:
COPILOT_GITHUB_TOKEN>GH_TOKEN>GITHUB_TOKEN; cli-dispatch automatically
reuses gh auth token as GH_TOKEN when available. An active GitHub Copilot subscription is required.
- Balance: not queryable from the CLI.
/usageis interactive-only inside a Copilot REPL;
use https://github.com/settings/billing for real usage/limits.
- Same session dir as the others, so
sessions/watch/resume/killall work. - Babysitter subagent: the
cp-runnersubagent manages a Copilot delega
…
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: rbinar
- Source: rbinar/cli-dispatch
- License: MIT
- Homepage: https://medium.com/@rbinar/cli-dispatch-claudea-patron-deepseek-e-i%CC%87%C5%9F%C3%A7i-rol%C3%BC-veren-bir-plugin-b232803581fc
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.