We embed the Agent SDK (0.3.289, engine 2.1.289) in a desktop application on Windows, starting one non-interactive engine process per user message. We do not use cross-session messaging. We observe that each engine process nevertheless binds its inbox (a named pipe, \.\pipe\LOCAL\cc-msg-) and publishes a key file (..key) in the sessions folder under the config directory. Any process running as the same operating-system user that reads the key file can deliver text into the running conversation; it reaches the model framed as a message from another session.
Is there a supported way, for SDK-embedded use, to prevent the inbox from being bound at all, without bare mode? The documented setting crossSessionInbound: "refuse" drops inbound messages, but as documented the inbox is still bound and the key is still published.
We observe that setting the environment variable CLAUDE_CODE_HARBOR_KITE=0 prevents both the bind and the key file. Is that variable supported for this purpose, and will it remain?
With "refuse" in force, are all inbound frame kinds dropped, including control frames, or only user messages?
On macOS and Linux the auth line is optional. Is the socket's protection there solely the permissions of its directory?
When the engine process is terminated rather than exiting on its own, the key file and the session registry record remain on disk. Is the host expected to remove them?
Is there an SDK option to choose where the key file is written, or to have none written?
We embed the Agent SDK (0.3.289, engine 2.1.289) in a desktop application on Windows, starting one non-interactive engine process per user message. We do not use cross-session messaging. We observe that each engine process nevertheless binds its inbox (a named pipe, \.\pipe\LOCAL\cc-msg-) and publishes a key file (..key) in the sessions folder under the config directory. Any process running as the same operating-system user that reads the key file can deliver text into the running conversation; it reaches the model framed as a message from another session.
Is there a supported way, for SDK-embedded use, to prevent the inbox from being bound at all, without bare mode? The documented setting crossSessionInbound: "refuse" drops inbound messages, but as documented the inbox is still bound and the key is still published.
We observe that setting the environment variable CLAUDE_CODE_HARBOR_KITE=0 prevents both the bind and the key file. Is that variable supported for this purpose, and will it remain?
With "refuse" in force, are all inbound frame kinds dropped, including control frames, or only user messages?
On macOS and Linux the auth line is optional. Is the socket's protection there solely the permissions of its directory?
When the engine process is terminated rather than exiting on its own, the key file and the session registry record remain on disk. Is the host expected to remove them?
Is there an SDK option to choose where the key file is written, or to have none written?