claude-delegate
amelnagdy/delegate-skills
Delegate coding tasks to a separate Claude Code session, review diffs, and land changes yourself.
What is claude-delegate?
Claude Delegate lets you orchestrate a bounded coding task by dispatching it to a separate Claude Code CLI process, then reviewing and committing the results. Use it only when a user explicitly asks to delegate implementation to another Claude session or the `claude` CLI.
- Dispatch a coding task brief to a separate Claude Code session via stdin
- Review diffs and gate outcomes before landing changes
- Resume interrupted sessions with delta briefs for rework
- Run tasks in read-only mode for inspection without edits
- Set resource limits (max turns, budget, timeout) and auto-compact windows
- Enforce shell sandbox on macOS, Linux, and WSL2 with explicit permission profiles
How to install claude-delegate
npx skills add https://github.com/amelnagdy/delegate-skills --skill claude-delegate- Claude CLI (`claude`) installed and authenticated (`claude auth status`)
- Node 18 or later
- Git repository at the target path
- On Linux/WSL2: Claude's sandbox dependencies installed
- macOS, Linux, or WSL2 (native Windows support pending)
How to use claude-delegate
- 1.Write a bounded task brief (no orchestrator history, include AGENTS.md constraints, instruct not to commit)
- 2.Run `node <skill-dir>/scripts/relay.mjs --brief brief.txt --cd /path/to/repo` with optional flags (--read-only, --resume-last, --session, --max-turns, --max-budget-usd, --autocompact, --timeout)
- 3.Wait for the relay to block until Claude exits and `result.json` is written
- 4.Review the implementer's edits, diffs, and gate outcomes; re-run project gates yourself
- 5.Commit only after gates pass and diffs are verified; resume the same session with a delta brief for rework
Use cases
- User asks 'have another Claude implement this feature' — dispatch the task and review the diff
- Orchestrate a large refactor across multiple bounded tasks by resuming sessions with delta briefs
- Inspect a task outcome without committing by running in read-only mode
- Enforce gates and security boundaries by reviewing implementer claims before landing
- Orchestrator agents (Claude Code, Cursor) that can run shell commands and read files
- Teams using multi-session workflows to separate task design from implementation
- Projects requiring explicit review and approval before code lands
claude-delegate FAQ
Only when the user explicitly asks to delegate to another Claude Code process or session (e.g., 'have another Claude implement this'). Do not use if the user asks the current Claude to implement directly.
The relay will exit with status 127 and write `status: "claude_unavailable"` to result.json. Verify `claude --version` and `claude auth status` succeed before dispatching. On macOS with sandboxed orchestrators, re-run the check outside the sandbox if Keychain access is blocked.
No. The relay never commits. You (the orchestrator) review the diff and gate outcomes, then commit only after verification. This ensures you own the judgment and the final state.
Echo a delta brief (e.g., 'replace the mocked test with the migrated fixture') and run `relay.mjs --session <id> --cd /path/to/repo`. Review the resumed run exactly like the first run.
It runs the implementer in `plan` mode with only Read, Glob, and Grep tools, no edits or shell. It compares git porcelain and fingerprints working-tree identity to detect changes without allowing them.
Full instructions (SKILL.md)
Source of truth, from amelnagdy/delegate-skills.
name: claude-delegate
description: >-
Delegate a coding task to a separate Claude Code CLI process or another Claude session as an
implementer, then review its diff and land it yourself. Use only when the user explicitly asks to
delegate implementation to Claude Code, another Claude session, or the claude CLI — for example,
"have another Claude implement this", "delegate this to Claude Code", or "run this queue through a
separate Claude session." Do not trigger merely because the current orchestrator is Claude, and do
not use when the user asks the current Claude to implement directly without delegation.
license: MIT
compatibility: Requires the claude CLI (Claude Code) installed and authenticated, Node 18+, and git. The orchestrating agent must be able to run shell commands and read files. Claude's shell sandbox requires macOS, Linux, or WSL2; native Windows launch is pending verification. The optional --autocompact flag requires claude 2.1.221 or newer.
metadata:
version: 0.5.0
Claude Delegate
You are the orchestrator. Delegate one bounded coding task to a separate implementer — a Claude Code CLI session — then review what it produced and land it yourself. You write the brief and own the judgment; the separate Claude session edits the working tree; you verify and commit.
This skill is not a signal for the current Claude to implement directly. Use it only after the human explicitly asks for delegation to another Claude Code process or session.
When not to use this
- The human asked the current agent to implement the task directly.
- The task is small enough to do inline and the human did not request delegation.
- The
claudeCLI is missing or unauthenticated (claude auth status). - The task needs a stronger host boundary than Claude Code's tool permissions and shell-only sandbox provide. Use an isolated container or VM for that requirement.
Prerequisites
claude --versionsucceeds.claude auth statusreports an authenticated session. On macOS the live credentials sit in the login Keychain; when the orchestrator's own sandbox blocks Keychain access (Codex's sandbox does),claudefalls back to a possibly stale credentials file and reportsloggedIn: falseeven though the login is valid. Re-run the check — and the dispatch itself — with that sandbox escalated or outside it before concluding the CLI is unauthenticated.- The target repository is the directory passed with
--cd. - On Linux/WSL2, Claude's sandbox dependencies are installed. The normal relay profile is configured to fail when the sandbox is unavailable instead of silently running shell commands unsandboxed. Existing merged settings can still affect the effective boundary.
The loop
1. Write the brief
The separate session has no orchestrator chat history. It receives the brief on stdin and can inspect the target working tree.
Claude Code automatically discovers the target project's CLAUDE.md and normal local Claude
configuration because the relay does not use --bare. It does not generically auto-load
AGENTS.md. Read AGENTS.md yourself and copy every load-bearing constraint and the real gate
commands into the brief. Tell the implementer not to commit. Keep one task per brief.
Template and details: references/writing-the-brief.md.
2. Dispatch
node "<skill-dir>/scripts/relay.mjs" --brief brief.txt --cd /path/to/repo
# review/diagnosis only: add --read-only
# continue the latest session: add --resume-last
# continue the recorded session: add --session <id>
# choose limits: add --max-turns 40 --max-budget-usd 10
# set the auto-compact window: add --autocompact 400k
# hard relay deadline: add --timeout 2h
# inspect every option: node .../relay.mjs --help
<skill-dir> is this installed skill directory, the folder containing this SKILL.md.
The relay runs claude -p --output-format stream-json --verbose, sends the brief through stdin, and
writes artifacts under the system temp directory by default. It never uses --bg or --bare, and it
never commits. See references/dispatch-and-poll.md.
--autocompact <auto|tokens> passes Claude Code's auto-compact window setting on every new or resumed invocation, and needs Claude Code 2.1.221 or newer — older builds fail the dispatch with unknown option '--autocompact'. The installed CLI owns the accepted range (auto, or 100k–1M tokens); the relay records the requested value but does not claim that Claude applied or enforced it.
3. Wait
The relay blocks until Claude exits. Use the orchestrator's background-command facility, or run it in
the foreground and wait. Completion means the process exited and result.json exists.
- A pre-run usage error exits 2 and writes no
result.json. - A missing
claudeexits 127 and writesstatus: "claude_unavailable". - Timeout and caught relay signals terminate the whole implementer process tree and preserve an outcome artifact.
Read finalMessage, touchedFiles, resultSubtype, and the raw artifact paths from result.json.
4. Review
Treat the implementer's report and gate outcomes as claims:
- Review edits to existing tests before a green gate means anything.
- Re-run the project's actual gates yourself.
- Read the complete diff against the brief, starting with
touchedFiles. - Inspect untracked and staged content as well as the ordinary diff.
- Run relevant guard skills if installed.
Full checklist: references/review-and-land.md.
5. Land
The orchestrator commits only after the gates pass and the diff holds. For rework, resume the same Claude session with a delta brief:
echo "Keep the implementation, replace the mocked DB test with the migrated fixture, and remove the
unused import." | node "<skill-dir>/scripts/relay.mjs" --session <id> --cd /path/to/repo
Review a resumed run exactly like the first run.
Permission profiles
The normal profile is deliberately explicit:
acceptEditspermission mode.- Built-in tools restricted to Read, Glob, Grep, Edit, Write, and the platform shell.
- On macOS, Linux, and WSL2, Claude's shell sandbox is enabled with startup failure on missing dependencies and no unsandboxed retry. Commands that stay sandboxed are auto-approved so ordinary gates can run headlessly. The sandbox governs shell processes and their children only; merged local or managed sandbox settings can add effective paths or exclusions.
- Configured MCP discovery and Claude.ai connectors are disabled, all MCP tools are denied, and
skills, commands, and Claude's Agent tool are unavailable to the child. Project
CLAUDE.md, hooks, normal authentication, session persistence, and other local settings still load. - String rules deny common direct shell forms of
git commit,git push, and nestedclaude, plus any command containingclaude-delegate. Aliases, scripts, and wrappers can bypass them, so they are only a speed bump; the brief's no-commit instruction and orchestrator review remain the boundary.
Native Windows does not support Claude's shell sandbox. The relay restricts the tool surface and
pre-approves PowerShell so the run remains non-interactive, but that shell is not OS-isolated. Native
claude.exe and npm claude.cmd launch paths are implemented; Windows verification is pending.
--read-only uses plan mode with only Read, Glob, and Grep. It removes edit, write, and shell paths,
then compares parsed git porcelain and fingerprints the working-tree identity and index entries of
Git-visible paths that were already dirty.
readOnlyViolation is true when either signal proves a change, false when coverage is complete and
detects none, and null when coverage is incomplete. This is a reporting tripwire, not an OS boundary:
ignored paths and perfect restores are outside it, local hooks can write, and concurrent changes cannot
be attributed to Claude.
--dangerously-skip-permissions is an explicit opt-in to Claude's bypassPermissions mode. The
restricted tool surface, direct commit/push deny rules, and supported-platform shell sandbox remain,
but direct file tools can cross normal permission boundaries. Use it only with the human's explicit
acceptance.
Complementary to native Claude features
Claude subagents, agent teams, and background sessions are useful when the current Claude environment is already the orchestrator and native coordination is the goal. This skill is complementary: it provides a cross-orchestrator contract — self-contained brief → dispatch → artifacts → review → land — and keeps the commit with the orchestrator.
References
- references/writing-the-brief.md — context,
CLAUDE.mdversusAGENTS.md, real gates, report contract, and delta briefs. - references/dispatch-and-poll.md — flags, profiles, artifacts,
result.json, polling, and failure recovery. - references/review-and-land.md — generated-code review, the commit boundary, and session rework.
- references/multi-task-queues.md — sequential queues, progress tracking, constraint carry-forward, and final coherence.
Related skills
More from amelnagdy/delegate-skills and the wider catalog.

cline-delegate
Delegate coding tasks to Cline CLI as a background implementer, then review and land the diff.

codex-delegate
Delegate coding tasks to OpenAI Codex CLI, review the diff, and land it yourself.

commandcode-delegate
Delegate coding tasks to Command Code CLI as a background implementer, then review and land the diff.

copilot-delegate
Delegate coding tasks to GitHub Copilot CLI, review diffs, and land changes yourself.

cursor-delegate
Delegate coding tasks to Cursor Agent CLI, review diffs, and land verified changes yourself.

delegate-setup
Configure delegation lanes: map work types to implementer CLIs with optional model and effort dials.