Use when operating the Codex delegation MCP server and tools (delegate.spawn, delegate.question.*, delegate.cancel, github.merge confirmation flow), or when configuring delegation mode/tool_profile...
Use this skill to operate delegation MCP tools with delegation enabled by default (the only MCP on by default). Disable it only when required by safety constraints, and keep other MCPs off unless they are relevant to the task.
For shipped CO usage, default to this command path unless task constraints say otherwise:
codex-orchestrator flow --task <task-id>codex-orchestrator doctor --usage --window-days 30 --task <task-id>codex-orchestrator rlm --multi-agent auto "<goal>"delegation-usage is the canonical delegation workflow skill. If delegate-early is present, treat it as a compatibility alias that should redirect to this skill.
Multi-agent (collab tools) mode is separate from delegation. For symbolic RLM subcalls that use collab tools, set RLM_SYMBOLIC_MULTI_AGENT=1 (legacy alias: RLM_SYMBOLIC_COLLAB=1) and ensure your Codex CLI has features.multi_agent=true (collab is a legacy alias/name in some keys); collab tool calls are recorded in manifest.collab_tool_calls. If collab tools are unavailable in your CLI build, skip collab steps; delegation still works independently.
spawn_agent accepts one input style per call: either message (plain text) or items (structured input).message and items in the same spawn_agent call.spawn_agent falls back to default when agent_type is omitted; always set agent_type explicitly.[agent_type:<role>] on the first line and keep it aligned with agent_type.fork_context disabled by default for bounded streams; use fork_context=true only when the child must inherit prior thread context.agent_id (thread id). Current TUI collab rendering is id-based; do not depend on custom visible agent names.never; design child tasks to avoid approval/escalation requirements.spawn_agent, run wait and then close_agent for that same id before task completion.open_agent_ids ledger and append ids immediately after each successful spawn.open_agent_ids only after successful close_agent.open_agent_ids, then clear the ledger.agent thread limit reached, stop spawning, run close-sweep for known ids, retry once, and if still blocked surface a concise degraded-mode recovery note.git status --porcelain). After wait, diff against baseline and classify file changes by stream ownership.scripts/subagent-edit-guard.mjs for low-friction enforcement when the helper exists in the repo (start before spawn, finish after wait); canonical command examples live in docs/delegation-runner-workflow.md (section 3a). If the helper is absent, apply the same baseline/scope checks manually.Use this when delegation tools are missing in the current run (MCP disabled) and you want a background Codex run to handle delegation:
codex exec \
-c 'mcp_servers.delegation.enabled=true' \
"Use delegate.* tools to <task>. Return a short summary and any artifacts."
Optional (only if you need it):
--repo /path/to/repo only when you want to pin the server to a repo even if Codex is launched outside that repo (default uses cwd).-c 'features.skills=false' for a minimal, deterministic background run.-c 'delegate.mode=question_only' when the child only needs delegate.question.* (and optional delegate.status).-c 'delegate.mode=full' when the child needs delegate.spawn/pause/cancel (nested delegation / run control).delegate.spawn is missing, re-register the MCP server with full mode (server config controls tool surface):codex mcp remove delegationcodex mcp add delegation --env 'CODEX_MCP_CONFIG_OVERRIDES=delegate.mode="full"' -- node /path/to/@kbediako/codex-orchestrator/dist/bin/codex-orchestrator.js delegate-servercodex mcp add delegation --env 'CODEX_MCP_CONFIG_OVERRIDES=rlm.max_subcall_depth=8;rlm.wall_clock_timeout_ms=14400000' -- node /path/to/@kbediako/codex-orchestrator/dist/bin/codex-orchestrator.js delegate-serverFor deeper background patterns and troubleshooting, see DELEGATION_GUIDE.md.
For runner + delegation coordination (short --task flow), see docs/delegation-runner-workflow.md.
delegate.mode=question_only unless the child truly needs full tool access.codex exec only for pre-task triage (no task id yet) or when delegation is unavailable; copy outcomes into the spec once it exists.codex-orchestrator setup --yescodex-orchestrator mcp enable --yescodex-orchestrator delegation setup --yescodex-orchestrator doctor).codex mcp add delegation -- node /path/to/@kbediako/codex-orchestrator/dist/bin/codex-orchestrator.js delegate-server--repo /path/to/repo to pin the server to one repo (not recommended if you work across repos).delegate-server is the canonical name; delegation-server is supported as an alias.codex-orchestrator delegation cleanup-stale --yes-c 'mcp_servers.delegation.enabled=true' only works after registration.delegate.* tools are missing mid-task, start a new run with:codex -c 'mcp_servers.delegation.enabled=true' ...codex-orchestrator aligned with the current CO compatibility or adoption target (codex-cli 0.135.0 for local ChatGPT-auth/appserver posture).0.135.0 CO-local posture keeps the onboarding-relevant behaviors from 0.124.0: codex exec accepts a prompt argument plus piped stdin, and codex login --device-auth is available for non-browser sign-in fallback.gpt-5.4 only as the fallback packaged default because it may still appear as the app-server isDefault.codex-orchestrator --versionnpm i -g @kbediako/codex-orchestrator@latestnpx -y @kbediako/codex-orchestrator@<version> delegate-servercodex is the default path. If you use a custom Codex fork, fast-forward it regularly from upstream/main.scripts/codex-cli-refresh.sh --repo /path/to/codex --align-onlyscripts/codex-cli-refresh.sh --repo /path/to/codex --force-rebuildexport CODEX_CLI_USE_MANAGED=1 (without this, stock/global codex stays active).--no-push only when you intentionally want local-only alignment without updating origin/main.codex-orchestrator codex setup --source /path/to/codex --yes --forcedefault, explorer, worker, and awaiter. researcher is user-defined.spawn_agent omission defaults to default; require explicit agent_type for every spawn.[agent_type:<role>].spawn_agent -> send_input -> wait/resume_agent -> close_agent).0.135.0, built-in explorer continues to inherit top-level model defaults unless a role config_file overrides it.gpt-5.5 / xhigh when available in ChatGPT-auth Codex sessions.gpt-5.4 / xhigh as fallback values.~/.codex/config.toml:model = "gpt-5.4"review_model = "gpt-5.4"model_reasoning_effort = "xhigh"features.multi_agent=true and older Codex behavior, [agents] max_threads = 12 is the seeded baseline. For Codex CLI 0.125+ with features.multi_agent_v2=true, do not write or recommend agents.max_threads; upstream rejects the key, so doctor/default setup must omit it. For Codex CLI 0.128+, the v2-specific cap features.multi_agent_v2.max_concurrent_threads_per_session is user-owned tuning and CO does not seed it by default. Keep explicit max_depth = 4 only when your local Codex parser accepts it, and treat max_spawn_depth as a legacy local override rather than current baseline guidance[agents.explorer] undefined unless you intentionally want to override built-in explorer behavior[agents.explorer_fast] -> ~/.codex/agents/explorer-fast.toml (gpt-5.3-codex-spark, file/codebase search only)[agents.awaiter] override -> ~/.codex/agents/awaiter-high.toml when you want awaiter at gpt-5.4 + high while preserving awaiter instructions[agents.worker_complex] -> ~/.codex/agents/worker-complex.toml (gpt-5.4, xhigh)gpt-5.5 for delegated/review surfaces when access smoke validates current ChatGPT-auth/appserver availability; otherwise use the portable gpt-5.4 fallback defaults.isDefault may still report gpt-5.4 even when newer local models are available.8/2 for constrained/high-risk lanes, legacy 6/1/1 as break-glass when an older parser/runtime still consumes spawn-depth caps.codex-orchestrator init codex; when features.multi_agent_v2=true, init/default setup must omit agents.max_threads and leave any features.multi_agent_v2.max_concurrent_threads_per_session cap to explicit user-owned configuration.codex startup fails with invalid type: integer ... expected struct AgentRoleToml under [agents], remove only the live max_depth and max_spawn_depth keys from ~/.codex/config.toml and leave the role subtables unchanged.When delegate.* is missing in the current session, immediately spawn a background Codex run with delegation enabled and hand it the narrow task. Use codex exec so it completes without interaction and you can capture output:
codex exec \
-c mcp_servers.delegation.enabled=true \
"Use delegate.* tools to <task>. Return a short summary and any artifacts."
Guidance for background runs:
codex exec streams progress to stderr and prints the final message to stdout, so you can pipe or redirect safely.--json for JSONL events, or -o <path> to write the final message to a file while still printing to stdout.codex exec resume --last "<follow-up>" to continue the same session.confirmation_required; approvals happen via the UI/TUI and the run resumes after approval.codex-orchestrator start ....codex exec does not create an orchestrator manifest. If the child must call delegate.question.* or delegate.status/pause/cancel, pass a real .runs/<task>/cli/<run>/manifest.json via parent_manifest_path/manifest_path (e.g., run codex-orch start diagnostics --format json --task <task-id> to get one; or use export MCP_RUNNER_TASK_ID=<task-id> if you prefer env vars).MCP_RUNNER_TASK_ID does not cause codex exec to emit .runs/** manifests; use codex-orchestrator start <pipeline> --task <id> when manifest evidence is required.mcp_servers.delegation.enabled = true in ~/.codex/config.toml (only MCP on by default).codex -c 'mcp_servers.delegation.enabled=true' ...codex-orch start <pipeline> --format json --task <task-id> over export MCP_RUNNER_TASK_ID=... for a shorter, explicit task id.delegate.spawn when you want a child run with a reduced tool surface.delegate.mode explicitly: question_only or full.question_only: only constrains the delegate.* namespace (question queue + optional status).full: enables the full delegate tool surface, including nested delegation.full only when the child needs delegate.spawn/pause/cancel (nested delegation or run control). Other tools (shell/web/filesystem/etc) are governed by delegate.tool_profile + repo allowlists and can be available in question_only.github.* registration is independent of delegate.mode and may still be available if repo-allowed.delegate.tool_profile separately to the minimum necessary tools.delegate.allowed_tool_servers.delegate.allowed_tool_servers, the cap defaults to [] and extra tools are ignored.^[A-Za-z0-9_-]+$; invalid entries (e.g., ;, /, \n, =) are ignored.github.* tools are not gated by delegate.tool_profile; they are controlled by repo GitHub allowlists.delegate.allowed_tool_servers (it may have changed).delegate.tool_profile minimal; avoid networked tools unless required.full when delegate.allow_nested=true and you intend recursion.delegate.mode (server tool surface) is different from delegate_mode (input to delegate.spawn for the child run).delegate.spawn defaults to start_only=true and returns once a new manifest is detected; set start_only=false for legacy synchronous behavior (waits for child exit), which is subject to tool-call timeouts.Goal: <one sentence>
Scope: <files/areas to touch>
Allowed tools: <tool_profile list>
Constraints: <must/ must-not>
Output: <patch + short summary>
Evidence: write detailed notes to artifacts/<name>.md (no long logs in chat)
Acceptance: <3-5 bullets>
delegate.question.enqueue to send an escalation to the parent run.delegate.question.poll to fetch status/answer. wait_ms is capped to 10s per call. If you need longer waits, loop with brief pauses:repeat:
poll(wait_ms=10000)
if status in {answered, expired, dismissed}: stop
sleep/backoff briefly (e.g., 250–500ms, with jitter)
expired, check fallback_action (from delegate.question.expiry_fallback) and follow it; default is pause.confirm_nonce. The runner injects it after approval.confirmation_required and the run may pause.confirmation_required, do not retry the action; wait for approval/resume. If it expires, re‑request with a fresh tool call.manifest_path (delegate.status/pause/cancel) to locate the run.parent_manifest_path for the same reason.wait_ms never blocks longer than 10s per call; use polling.start_only=true (default) to avoid tool-call timeouts. If you must use start_only=false, keep runs short or run long jobs outside delegation (no question queue).couldn't find remote ref ...; set CODEX_CLOUD_BRANCH to a pushed branch (typically main) before cloud execution.CODEX_ORCHESTRATOR_CLOUD_FALLBACK=deny.confirm_nonce from model/tool input; it is runner‑injected only.control_endpoint.json in the run directory; older runs may not have it.spawn_agent rejects calls that include both message and items.agent_type and add first-line [agent_type:<role>] tags.close_agent calls accumulate open threads and can trigger agent thread limit reached; always finish spawn -> wait -> close_agent per id.collab-subagents-first: for stream decomposition and parent/subagent ownership discipline.collab-deliberation: for option generation before implementation when decisions are ambiguous/high-impact.standalone-review: for checkpoint reviews after delegated implementation streams.long-poll-wait: for patience-first monitoring of long-running delegated/cloud jobs.