Skip to content

Agent SDK embedded use — can the cross-session messaging inbox be left unbound? #496

Description

@brett369369

We embed the Agent SDK (0.3.289, engine 2.1.289) in a desktop application on Windows, starting one non-interactive engine process per user message. We do not use cross-session messaging. We observe that each engine process nevertheless binds its inbox (a named pipe, \.\pipe\LOCAL\cc-msg-) and publishes a key file (..key) in the sessions folder under the config directory. Any process running as the same operating-system user that reads the key file can deliver text into the running conversation; it reaches the model framed as a message from another session.

Is there a supported way, for SDK-embedded use, to prevent the inbox from being bound at all, without bare mode? The documented setting crossSessionInbound: "refuse" drops inbound messages, but as documented the inbox is still bound and the key is still published.
We observe that setting the environment variable CLAUDE_CODE_HARBOR_KITE=0 prevents both the bind and the key file. Is that variable supported for this purpose, and will it remain?
With "refuse" in force, are all inbound frame kinds dropped, including control frames, or only user messages?
On macOS and Linux the auth line is optional. Is the socket's protection there solely the permissions of its directory?
When the engine process is terminated rather than exiting on its own, the key file and the session registry record remain on disk. Is the host expected to remove them?
Is there an SDK option to choose where the key file is written, or to have none written?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentationenhancementNew feature or requestquestionFurther information is requested

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions