@@ -910,14 +910,22 @@ persona session, add it to the persona's `mcpServers` block.
910910agentworkforce agent [--install-in-repo] [--no-launch-metadata] < persona> [@< tier> ]
911911```
912912
913- By default, claude and opencode sessions run inside a sandbox mount — see
914- [ ** Sandbox mount** ] ( #sandbox-mount ) below. ` --install-in-repo ` opts out.
913+ By default, simple prompt/MCP launches run directly in the real cwd with
914+ normal harness auth and session-scoped argv/config inputs. The CLI does not
915+ change ` $HOME ` , run Claude with ` --bare ` , or otherwise hide OAuth/keychain
916+ credentials in this direct path. A sandbox mount is created only when the
917+ persona needs filesystem mediation: declared ` mount ` rules, sidecar/config
918+ files that must appear in the harness cwd, or non-Claude skill installs that
919+ would otherwise write repo-relative artifacts. ` --install-in-repo ` opts out of
920+ session staging and lets installers write to the repo's conventional harness
921+ directories.
915922
9169231 . Resolves the persona, walks the cascade, resolves ` $VAR ` refs.
917- 2 . ** Stages skills outside the repo by default** (claude interactive only —
918- see ** Skill staging** below). For codex / opencode, or when
919- ` --install-in-repo ` is passed, falls back to the legacy repo-relative
920- install path (` .claude/skills/ ` , ` .agents/skills/ ` , ` .skills/ ` ).
924+ 2 . ** Stages skills outside the repo by default** for Claude interactive
925+ sessions — see ** Skill staging** below. Codex/opencode skill installs still
926+ require a sandbox mount unless ` --install-in-repo ` is passed, because their
927+ installers write repo-relative paths (` .agents/skills/ ` , ` .skills/ ` ,
928+ lockfiles).
9219293 . Runs skill install (` prpm install … ` ) if the persona declares any skills,
922930 using the computed target (stage dir or repo).
9239314 . Execs the harness binary with stdio inherited:
@@ -1005,7 +1013,7 @@ the working tree, and the session only sees the skills the persona declares
10051013** Opt-out — ` --install-in-repo ` :**
10061014
10071015Pass ` --install-in-repo ` to fall back to the legacy behavior (skills land in
1008- the repo's ` .claude/skills/ ` directory, cleaned on exit):
1016+ the repo's harness directory, then are cleaned on exit):
10091017
10101018``` sh
10111019agentworkforce install @agentworkforce/personas-core --persona code-reviewer
@@ -1018,24 +1026,33 @@ stage dir conflicts with something else (network filesystem, read-only
10181026
10191027** Caveats for V1:**
10201028
1021- - ** Claude harness only.** codex and opencode continue to install into their
1022- conventional repo-relative directories. The SDK throws if ` installRoot ` is
1023- passed with a non-claude harness .
1029+ - ** Claude installRoot only.** codex and opencode do not support
1030+ out-of-repo install roots yet. When they declare skills, the CLI uses a
1031+ sandbox mount by default so installer output stays out of the real repo .
10241032- ** No cache layer yet.** Every interactive session runs a fresh prpm install
10251033 into a new stage dir. A ` ~/.agentworkforce/workforce/cache/ ` content-addressed cache
10261034 is planned but not wired up.
10271035
10281036## Sandbox mount
10291037
1030- By default, claude and opencode interactive sessions run inside a
1038+ Interactive sessions normally avoid a filesystem mirror. The CLI creates a
10311039[ ` @relayfile/local-mount ` ] ( https://www.npmjs.com/package/@relayfile/local-mount )
1032- mount that hides repo-level harness configuration from the session, applies
1033- the persona ` mount ` block plus Relayfile ` .agentignore ` / ` .agentreadonly `
1034- rules, and routes skill-install writes into the sandbox — so the model sees
1035- persona context + user-level context, and only the project files the mount
1036- exposes. Codex sessions never mount (no harness-side support).
1040+ only when a persona needs filesystem-level behavior:
10371041
1038- ` --install-in-repo ` opts out and runs against the real cwd.
1042+ - ` mount.ignoredPatterns ` or ` mount.readonlyPatterns ` .
1043+ - Persona sidecars (` claudeMd ` / ` agentsMd ` ) that must be materialized as
1044+ ` CLAUDE.md ` / ` AGENTS.md ` without writing into the real repo.
1045+ - Harness config files such as opencode's per-session ` opencode.json ` .
1046+ - Codex/opencode skill installs, whose providers still write repo-relative
1047+ directories and lockfiles.
1048+
1049+ When the mount is active, it hides repo-level harness configuration from the
1050+ session, applies the persona ` mount ` block plus Relayfile ` .agentignore ` /
1051+ ` .agentreadonly ` rules, and routes sandbox-only writes away from the real
1052+ checkout.
1053+
1054+ ` --install-in-repo ` prevents the mount from being used for installer isolation
1055+ and runs installers against the real cwd.
10391056
10401057The CLI reads these files from the project root before creating the mount:
10411058
@@ -1072,10 +1089,11 @@ the repo):
10721089 still load. The mount scrubs the * project* , not the user. To exclude
10731090 user-level context too, launch under a scratch ` $HOME ` .
10741091- ** Persona skills.** For claude, the ` --plugin-dir ` passed to the harness
1075- resolves to an absolute path * outside* the mount, so staged skills from
1076- ` ~/.agentworkforce/workforce/sessions/<id>/claude/plugin/ ` load normally. For
1077- opencode, the install runs inside the mount so the writes land in the
1078- sandbox.
1092+ resolves to an absolute path under
1093+ ` ~/.agentworkforce/workforce/sessions/<id>/claude/plugin/ ` , so simple
1094+ Claude personas do not need a mount just to load staged skills. For
1095+ codex/opencode, the install runs inside the mount when skills are declared
1096+ so repo-relative installer output lands in the sandbox.
10791097- ** Keychain auth.** The mount does not pass ` --bare ` ; it only hides
10801098 files. Claude Code's macOS keychain login stays active.
10811099- ** Persona ` mcpServers ` .** Still passed via ` --mcp-config ` — unaffected
@@ -1089,9 +1107,10 @@ the repo):
10891107
10901108### Session layout
10911109
1092- Both the skill install root and the sandbox mount live under a single
1093- session directory. The session id (` <personaId>-<base36-timestamp>-<hex> ` )
1094- is generated once and both paths are derived from it:
1110+ When a run needs session artifacts, the skill install root and any sandbox
1111+ mount live under a single session directory. The session id
1112+ (` <personaId>-<base36-timestamp>-<hex> ` ) is generated once and both paths are
1113+ derived from it:
10951114
10961115```
10971116~/.agentworkforce/workforce/
@@ -1105,22 +1124,23 @@ is generated once and both paths are derived from it:
11051124 └── <mirrored project tree, minus the hidden patterns>
11061125```
11071126
1108- ` @relayfile/local-mount ` handles mount creation, process spawn,
1109- SIGINT/SIGTERM forwarding, write syncback, and cleanup on exit. The
1110- agentworkforce CLI just wires the paths and passes the persona 's argv .
1127+ ` @relayfile/local-mount ` handles mount creation, write syncback, and cleanup
1128+ when the conditional mount branch is active. Plain direct launches skip this
1129+ tree walk entirely and keep the harness 's normal auth lookup path .
11111130
11121131### Example
11131132
11141133``` sh
1115- # Interactive persona session with the repo's CLAUDE.md, .claude/, and
1116- # .mcp.json hidden — session sees the persona's staged skills plus your
1117- # user-level ~/.claude/CLAUDE.md, nothing else from this repo .
1118- agentworkforce install @agentworkforce/personas-core --persona code-reviewer
1119- agentworkforce agent code-reviewer@best
1134+ # Interactive persona session with explicit filesystem policy. This uses
1135+ # Relayfile so the session sees only the paths allowed by the persona and
1136+ # project .agentignore/.agentreadonly rules .
1137+ agentworkforce install @agentworkforce/personas-core --persona proactive-agent-builder
1138+ agentworkforce agent proactive-agent-builder
11201139```
11211140
1122- On exit: mount is synced back to the real repo, then torn down; skill
1123- stage dir is cleaned up by the existing ` rm -rf ` cleanup command.
1141+ On exit, mounted runs sync changes back to the real repo, then tear down the
1142+ mount; the skill stage dir is cleaned up by the existing ` rm -rf ` cleanup
1143+ command.
11241144
11251145## Selecting a harness per tier
11261146
0 commit comments