hyperhive/hive-subagent-mcp
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas d6c8cd5a6f subagent: hand a subagent its parent's built-in tools, and no others
`build_config` spawned a subagent with `--dangerously-skip-permissions`
and no `--tools` at all, so it got claude's entire built-in set —
`SendMessage` and `ListAgents` (message peers, or the operator, as its
parent), `Task*` including `TaskStop`, which takes an *agent* id and so
reaches clean outside the run, `Cron*`, `RemoteTrigger` and
`EnterWorktree`/`ExitWorktree`. None of that is part of "do this bounded
task in this directory", and none of it is something the parent agent
itself can do: the harness has always passed `--tools`.

Pass the same one. The value comes from
`hive_sh4re::permissions::builtin_tools_arg()` — literally the function
the harness resolves its own session with — so the subagent's set is the
parent's set, `HIVE_TOOL_GROUPS` and all. That inheritance is the
requirement, not an implementation detail: a hardcoded subagent list
would hand `WebFetch`/`WebSearch` to the subagent of an agent without the
`web_tools` group, which is a privilege escalation, and would drift from
the parent's list the first time anyone added a tool to either.

`--tools` is the real gate: it holds under
`--dangerously-skip-permissions`, unlike `--allowedTools`, which only
auto-approves prompts. It does not filter MCP tools, so the
`goal_reached`/`need_help` signal surface is deliberately unnamed in it
and survives on `--strict-mcp-config` alone.

`build_config`'s doc comment claimed `strict_mcp_config` was *the* safety
property and that a subagent got "nothing implicit and nothing more".
That was false for built-ins, and is what hid this gap for as long as it
did; it now says which flag covers which half and that neither
substitutes for the other.

An empty `--tools` value parses as *unset* and grants more than omitting
the flag, so an empty resolution can only be a bug — `build_config`
asserts against it and a test pins the non-emptiness alongside the
subset-of-parent property.

Refs #4416
2026-09-15 17:40:27 +02:00
..
src subagent: hand a subagent its parent's built-in tools, and no others 2026-09-15 17:40:27 +02:00
Cargo.toml subagent: hand a subagent its parent's built-in tools, and no others 2026-09-15 17:40:27 +02:00
README.md subagent: give each run its own signal URL, and drop the name argument 2026-09-14 22:24:51 +02:00

hive-subagent-mcp

Per-agent daemon (hive-subagent-daemon) that spawns nested headless claude sessions on request and serves the tool surface (start/continue/status/interrupt, plus a separate subagent-facing goal_reached/need_help route, one per-session URL) directly over streamable-http. No stdio bridge, no per-turn respawn — an agent's claude reconnects to the same stable URL every turn.

Independent of hive-bash-mcp — a subagent spawns a full nested claude session, a much heavier capability than a bash command, worth its own deployable/restartable unit.

Shape

One bin (hive-subagent-daemon, src/main.rs) built from the crate's own lib (src/lib.rs):

  • session.rs — the actual claude-facing logic: Claude::spawn + RunningClaude::wait/cancel_handle (not InfiniteSession::run, which has no cancel handle to reach in — see the module doc for the v1 scope this trades away), the turn-continuation loop a goal switches on, and the in-memory maps that are the only state this daemon keeps (no task files — a restart stops whatever's running; the actual claude session is the durable store, found again by name via hive_claude::SessionStore).
  • mcp.rs — the rmcp tool routers (the parent's start/continue/status/interrupt on /mcp, the subagent's goal_reached/need_help on /signal/mcp/<token>) + serve_http. Neither signal tool takes a session name: the token in the path is minted per run and resolved to a session before dispatch, so a subagent has no way to name — and therefore no way to signal — a sibling. One route with a path parameter, because the Router is built once at startup and sessions come and go for the daemon's whole life.
  • paths.rs — the in-agent todo-socket path.