Installs into .claude/skills of the current project.
Are you the author of Agent Knock Knock?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/scotthuang-agent-knock-knock)
---
name: agent-knock-knock
description: Control local Codex and Claude Code through shared tmux or Herdr terminals with Agent Knock Knock.
---
# Agent Knock Knock
Use this skill when the user explicitly invokes `AKK`, `akk`, or `Agent Knock Knock`, or asks a supported controller Host to inspect or control a coding-agent terminal listed by AKK.
AKK supports Codex and Claude Code that are already running inside tmux or local Herdr `0.8.0`. It never launches a coding agent. The controller Host, terminal host, AKK, and coding agent must run as the same OS user.
Treat `AKK` and `akk` the same way.
## Role
The controller Host interprets the user's request, sends the requested work into the selected shared terminal, handles actionable callbacks, and reports the outcome. The coding agent performs the engineering work in its existing tmux or Herdr terminal.
Keep the user's requested scope and approval boundaries. Do not expand a task, approve a permission, interrupt a process, or close a managed record unless the user request or an explicit trusted policy authorizes that action.
## Chat Routing
Use the `/akk` command for slash-command syntax. Use the Agent Knock Knock plugin tools for natural-language AKK requests.
Core slash-command forms:
- `/akk <task>`: send a new task only when exactly one send-ready coding-agent pane exists across all workspaces.
- `/akk <selector>: <message>`: resolve one exact eligible AKK session and create a new Turn for the message.
- `/akk list`: list live coding-agent terminals, their current or recent managed-turn context, and durable Terminal Watches.
- `/akk watch <exact-terminal-id>`: observe one exact user-selected terminal without submitting a task or creating a Session or Turn; prefer an exact task anchor and otherwise use a clearly labeled best-effort terminal-activity Watch.
- `/akk unwatch <watch-id>`: cancel only that observation; do not interrupt or otherwise change the TUI task.
- `/akk threads <exact-terminal-id>`: list verified native threads that may be resumed in one exact terminal.
- `/akk models <exact-terminal-id>`: inspect the exact native model and reasoning-effort catalog for one verified idle terminal.
- `/akk repair-model-control <exact-terminal-id>`: dismiss only a currently advertised exact stale profiled Codex 0.154.0/0.155.1 `/model` Composer surface or open native model picker and prove an empty Composer.
- `/akk set-model <exact-terminal-id> <advertised-model-id> <advertised-reasoning-effort>`: consume that displayed catalog once and change only the advertised semantic tuple.
- `/akk permissions <exact-terminal-id>`: inspect the idle Codex pane’s current permission mode and native built-in choices.
- `/akk set-permissions <exact-terminal-id> <advertised-mode-id>`: apply the user-selected mode from that immediately preceding catalog.
- `/akk new-thread <exact-terminal-id>` or `/akk clear-thread <exact-terminal-id>`: switch that idle terminal to a verified clean native context without creating a Turn.
- `/akk resume-thread <exact-terminal-id> [uuid|previous|number|@short-id]`: list candidates when the selection is omitted, or resume one exact snapshot-bound choice without creating a Turn. `previous` also accepts the human phrase `刚才那个`.
- `/akk status [turn-selector|terminal-watch-id]`: inspect one live terminal, exact managed Turn, or exact Terminal Watch.
- `/akk respond <turn-selector>: <answer>`: answer a coding-agent question inside a `waiting_for_openclaw` Turn.
- `/akk cancel <turn-selector>`: interrupt the exact Turn without closing its terminal pane.
For human-facing ordinary-send slash forms, a selector may be `codex`, `claude`, `only`, `latest`, or an `@short-ref` returned by `AKK list`. These selectors are only a resolution layer and fail closed when the target is missing or ambiguous. The v30 structured-tool contract never exposes a selector or opaque authority value: the model supplies semantic IDs only. The agent-neutral `terminal_user_explicit_composer_policy` advertises `replace_current_composer_and_submit`; the old Codex-named field is a v28 compatibility alias only. `send({session_id,request})` is strict `session_exact`; `send({terminal_id,request})` is either managed `terminal_follow_current` or user-priority `terminal_user_explicit`, exactly as advertised; the two target fields are mutually exclusive, and both may be omitted only when AKK must prove one unique send-ready pane. Codex and Claude Code `terminal_user_explicit` depend on the exact live terminal/process, a scanned non-blocked approval state, and no proven input-owning questionnaire, editor, menu, history search, or read-only viewer—not ordinary main-Composer visibility, stability, exactness, parsed working activity, existing draft contents, or AKK Store, Turn, Session, transfer, transition, ledger, or ownership. An unreviewed Codex frontend is the narrower exception: physical Send requires a recognized styled Composer before clearing and a fresh empty styled Composer before task text. Profiled Codex 0.154.0/0.155.1 exact collapsed async-question summaries leaves the main Composer sendable; an expanded, clipped, or ambiguous async editor and an active-writer resume viewer remain zero-input boundaries. Both advertise `replace_current_composer_and_submit`: Codex physical fallback sends `C-u` once; Claude Code physical fallback uses a sentinel-backed native `C-s` stash-clear transaction that is independent of the cursor position and does not interrupt an active turn, then proves the main Composer empty. Each injects the request, waits through the paste window, and dispatches Enter exactly once. After text injection, Composer observation must never veto Enter. AKK tries managed delivery where its strict empty-Composer pre-input authority exists; after either agent's user-explicit text injection, that path follows the same no-Composer-veto Enter rule. A source-less Codex terminal with zero, one, or many pre-existing rollout roots freezes that full candidate set before input and binds only the unique rollout that later persists the exact request hash; a unique stale root is never assumed to be foreground. If managed preparation still fails before input, AKK sends once without a managed callback Turn, then best-effort attaches the prepared exact request-bound or clearly labeled terminal-activity Watch and releases stale management. Watch persistence failure is a warning and never revokes or retries a successful Send; an unsafe or uncertain native probe still stops before task text. Native inspection and native lifecycle input remain exact-empty-only. With runtime durability, an omitted target binds its `message_id` to the first selected physical terminal and existing or uncertain same-ID evidence rejects replay. If fresh durability is unavailable, user priority wins: AKK proceeds with a warning, and the degraded result must not be automatically retried. Once clear or request input may have occurred, an uncertain result must not be automatically retried. Read Send results as orthogonal facts: `terminal_input_dispatched`, `agent_acceptance`, `management_mode`, `observation_mode`, and `capabilities` distinguish physical dispatch from durable native acceptance and callback/interaction authority; do not infer one from another. If the result returns `observation_mode="terminal_watch"`, wait for that callback and retain `watch-status` as the recovery path. The only non-ordinary Send form is an exact `send({turn_id})` copied unchanged from a current `available_actions.retry_submission`; it accepts no request text or other target and requires explicit user confirmation. Native-thread actions use the full `terminal_id`, never an `@short-ref`. Other managed controls use `turn_id`; terminal-scoped approval uses `terminal_id` after explicit user confirmation. The trusted plugin/CLI derives terminal, binding, candidate, prompt, composer, handoff, and compare-and-swap fences privately. Never ask the user or model to copy draft text, a composer digest, a token, fingerprint, revision, binding ID/generation, or handoff-only live native UUID from an action; `native_thread_id` is the intentional semantic UUID for resume. For every side effect, AKK must revalidate the selected agent PID and provider-owned terminal identity and revalidate the relevant approval prompt; Composer revalidation remains action-specific; unreviewed Codex frontends require the styled-Composer checks above.
The human-priority Codex path may proceed when the pane/process and complete open-rollout candidate inventory are exact even though no single foreground UUID can be selected, including a supported manual `/clear` whose new logical thread appears before its rollout materializes. The complete exact inventory domain binds the provider terminal, PID and process birth, workspace and canonical endpoint, and every open rollout's UUID, descriptor, device, inode, canonical path, and pre-submit byte offset. A `/clear` resume hint is advisory only, never routing or acceptance authority. Under the terminal lock, AKK isolates the predecessor, creates a separate zero-UUID provisional Session and Turn, sends the real task once, and binds only the single candidate rollout that durably accepts that exact request. A rollout-backed Codex row therefore advertises `terminal_follow_current` with `terminal_id`, not `session_exact`; a cached strict Session attempt rejects before task text and never downgrades itself. Only released predecessor Turn history from a strictly earlier binding epoch is excluded from current-send authority; unresolved current-epoch state still blocks. Use only the freshly listed semantic-ID action. Until promotion commits, strict `session_id` send, `respond`, managed `approve`, `cancel`, native lifecycle, callback delivery, and `native_inspect` remain unavailable. If delivery or acceptance is uncertain, do not retry automatically. Terminal-scoped manual Codex approval likewise exposes only `terminal_id`, requires explicit confirmation, leaves managed identity unchanged, never participates in auto-approval, and must not be retried blindly after an uncertain result.
For an exact-empty idle Codex pane whose native identity is ambiguous, List may advertise `identify_foreground` and `identify_and_send`. `agent_knock_knock_identify_foreground({terminal_id})` is explicit and Codex-only: it mutates no Store record but does send `/status` and Enter exactly once to the visible pane. Its 30-second proof is diagnostic, never reusable authority; do not feed its UUID or expiry into another tool. `agent_knock_knock_identify_and_send({terminal_id,request})` keeps one terminal lock across the probe and task and is the only actionable consumer of that observation. It still binds a durable Session/Turn only from unique exact request acceptance. A changed or uncertain probe sends no task and must not be retried automatically. Never invoke either action unless the current terminal row advertises it. List and Status do not run `/status`. Ordinary Send must not be redirected through these explicit identification tools implicitly; Codex 0.158.0 and later stable semantic versions may attempt their separate closed `/status` transaction for exact paginated Watch binding when the actual UI and read contract can be proven.
The private approval fence remains prompt-scoped. It binds the adapter-isolated exact unredacted approval region plus terminal/process identity, decision keys and label, prompt kind, working directory, reason/detail, and request or policy evidence. The whole-screen digest and redacted excerpt are diagnostic only: output outside the approval region may continue scrolling without invalidating the same reviewed prompt. After explicit user confirmation, the plugin/CLI retains a private confirmation offer and recaptures the region under lock. Any change inside the exact region—including a command or otherwise identically redacted secret—rejects and sends zero approval keys. Never expose, persist as public action data, log, infer, or reconstruct the raw prompt evidence or its opaque fingerprint.
Coding-agent versions distinguish missing verification from known protocol incompatibility. A merely unverified complete Codex or Claude Code `x.y.z` version keeps otherwise eligible actions advertised; preserve and surface its compatibility warning, then let runtime structure and postcondition checks decide success. Never suppress an action solely because its exact version lacks a regression-tested AKK profile. Known incompatible protocols disable their affected actions before input. Codex 0.157.0/0.157.1 create new durable TUI sessions with paginated history and may use a shared background server; AKK cannot yet bind that history to an exact managed task. Managed completion callbacks, native thread lifecycle actions, and automated native status dispatch remain unavailable; visible status cards can still be parsed. Explicit terminal Send and warning-bearing `terminal_activity` Watch remain available subject to native UI safety checks; that Watch reports best-effort activity notifications without proving exact task completion or granting question-response authority. `--no-daemon` does not restore legacy JSONL history for new sessions. Use only currently advertised mutation actions, and if input may already have occurred and the result is unproven, report the uncertainty and never retry automatically.
Codex 0.158.0 and later stable semantic versions may attempt an exact paginated task Watch instead of a legacy managed Session/Turn, including versions outside AKK's regression matrix. Before Send, AKK attempts a closed `/status` transaction in the available main Composer and validates the actual app-server read contract, Codex home, native thread, and task boundaries. A new version alone does not reject read-only observation. An existing exact Watch may continue across a compatible backend upgrade while retaining its original thread, turn, and request identity. When a Watch attaches, retain its `watch_id` for Status and callbacks; do not invent a `turn_id`. Read compatibility grants no native response authority: unreviewed frontend/backend pairs are notify-only, and backend drift withdraws existing executable question offers. Use fresh Status and its advertised capabilities before any response. This adapter does not establish managed session-only dispatch or native new/resume for paginated threads. Supported async responses offer only `steer_current_turn`, never `queue_next_turn`. A first Watch requested while a blocking modal already owns input cannot establish this binding and falls back to activity observation with manual question handling.
AKK discovers eligible panes across workspaces. When more than one target matches, choose one exact listed `terminal_id` for a structured tool or a listed selector for a human slash command; never guess based on a workspace name or path.
Natural-language forms:
- `AKK: <task>`: call `agent_knock_knock_send` with `request=<task>` and neither target ID. This succeeds only when exactly one send-ready pane exists. A scanned blocked approval or proven input-owning questionnaire, editor, menu, or read-only viewer vetoes physical Send; parsed working activity and an existing draft do not. Unreviewed Codex frontends require the styled-Composer checks above; reviewed physical Send paths do not require ordinary main-Composer visibility. Codex replaces the current Composer with `C-u`; Claude Code uses a sentinel-backed native `C-s` stash-clear transaction that is independent of the cursor position and does not interrupt an active turn, then proves the main Composer empty. Each injects the request and submits exactly once. Broken or stale AKK management activity records do not veto that independently verified live terminal/process.
- `AKK Codex: <task>`: list first, require one exact eligible Codex row, then call `agent_knock_knock_send` with that row's `terminal_id` and `request=<task>`.
- `AKK Claude: <task>`: list first, require one exact eligible Claude row, then call `agent_knock_knock_send` with that row's `terminal_id` and `request=<task>`.
- Requests to list AKK or local coding-agent work: call `agent_knock_knock_list`.
- Requests to observe an exact Codex or Claude Code terminal: normally call `agent_knock_knock_list` and copy that row's advertised `watch` action, then pass its complete `terminal_id`. If the user explicitly selected a complete exact terminal ID, missing `available_actions.watch` is not a veto: Watch may still be called with that ID. Never guess, shorten, or substitute a selector. AKK prefers an exact task anchor and otherwise records warnings and observes the terminal/process activity epoch.
- Requests to inspect an existing Terminal Watch: call `agent_knock_knock_status` with its authoritative `watch_id`. Requests to stop observing it: call `agent_knock_knock_unwatch` with that same `watch_id`. Never substitute a Session, Turn, terminal selector, or short reference.
- Requests to continue in the current terminal context after the human may have run `/clear`, `/new`, `/resume`, or an equivalent native operation: first call `agent_knock_knock_list`, then use only that exact terminal row's advertised `send({terminal_id,request})`; do not substitute the stale `session_id`.
- Requests to recover an AKK submission reported as uncertain: refresh `agent_knock_knock_list`. Only if the current exact Turn advertises `retry_submission`, explain that AKK will revalidate the immutable original request and may either press one Enter for the exact existing draft or retransmit that original text once after structured no-Enter proof and a positively empty composer. Require explicit user confirmation, then call the prefilled `agent_knock_knock_send({turn_id})` unchanged. Never add `request`, terminal/Session IDs, timeout fields, or callback route data, and never retry it automatically.
- Requests for the coding agent's native Codex status card or Claude Status panel: first call `agent_knock_knock_list`, then call `agent_knock_knock_native_inspect({terminal_id,inspection:"status"})` only when the exact terminal row advertises it; do not substitute AKK Turn status or ordinary send.
- Explicit requests to diagnose an ambiguous current Codex foreground: call `agent_knock_knock_identify_foreground({terminal_id})` only from that row's current action. Explain that it types one `/status` command, changes no Store state, and returns a non-authorizing 30-second observation. Never use the result as authority for a later mutation.
- Explicit requests to identify an ambiguous Codex foreground and send one task atomically: use the row's exact `agent_knock_knock_identify_and_send({terminal_id,request})` action. Do not synthesize this path for an ordinary Send or split it into identify-then-send calls.
- Requests to list resumable native threads for an exact terminal: call `agent_knock_knock_list_resumable_threads` with the terminal row's prefilled `terminal_id`.
- Explicit requests to start a new thread or clear context: call `agent_knock_knock_new_thread({terminal_id})` only from an advertised `new_thread` action.
- Explicit requests for low-level recovery of a listed binding conflict: after explicit user confirmation, call only the advertised `agent_knock_knock_reconcile_binding({terminal_id,conflicting_session_id})`. AKK derives its revision and binding fences privately, detaches the stale/conflicting binding without adopting the live thread, and requires a fresh list afterward. Do not use it in place of an advertised follow-current send.
- Explicit requests to resume prior native context: first call `agent_knock_knock_list_resumable_threads`; then call `agent_knock_knock_resume_thread({terminal_id,native_thread_id})` for one `resumable=true` candidate using its complete UUID. For “previous” / “刚才那个”, proceed only when the fresh result advertises `previous.available_actions.resume_thread`; use that exact semantic-ID action and never substitute the newest row. Human-facing numbers and short IDs are resolved privately and are never structured tool arguments.
- Requests to inspect current output or ask what a task is doing: call `agent_knock_knock_status`.
- A later ordinary request: refresh `agent_knock_knock_list` and use only the selected terminal row's advertised send. Use `send({session_id,request})` for `session_exact` or `send({terminal_id,request})` for `terminal_follow_current`; never substitute a retained Session or Turn identity.
- Requests to continue the current terminal context are ordinary terminal-scoped sends, not lifecycle actions. Use only a freshly advertised action carrying the exact `terminal_id` when a human-driven switch is present.
- An answer to a coding-agent question in a `waiting_for_openclaw` Turn: call `agent_knock_knock_respond` with its authoritative `turn_id` and `request=<answer>`.
- An answer to a native coding-agent interaction is a different flow: in the same controller conversation, call `agent_knock_knock_status` with exactly one authoritative subject (`{turn_id}` for a managed Turn or `{watch_id}` for a response-capable exact Watch), show the current pending `interaction_state` to the user, and require their explicit choice or text. Only when `capabilities.respond=true`, call `agent_knock_knock_respond_interaction` with that projection's same exact subject id, `interaction_id`, and typed `answers` using its opaque `question_id` and `option_id` values. For `kind="async_question"`, the coding task remains `working`; optionally pass a current advertised `delivery_mode` (default: `steer_current_turn`): `steer_current_turn` answers the running turn and `queue_next_turn` queues the answer for its next turn. For blocking `kind="questionnaire"`, omit `delivery_mode`. One call answers only the current step; call Status again before each later question or final confirmation. Never guess ids, translate a label into raw keys or menu indexes, answer a `manual_required` or secret-input state, or retry an uncertain response blindly.
- Requests to stop current work: call `agent_knock_knock_cancel`.
## Sessions and Turns
AKK's identity hierarchy is terminal → native Codex or Claude Code session → AKK session → Turns. `session_id` is the strict ordinary-send target for one exact native context. `terminal_id` is the deliberately different follow-current target that lets the user hand the pane's currently verified context back to AKK after a safe human-driven switch. Each accepted managed Send creates a distinct `turn_id` without clearing the native agent context; Codex paginated physical Send instead returns an independent exact-task or terminal-activity Watch when observation can be attached. A `turn_id` is used for history, callbacks, respond, status, approval, cancellation, renewal, callback retry, close, and the explicitly advertised submission-retry form of Send.
Use `agent_knock_knock_send` with `request` and neither `session_id` nor `terminal_id` only when the target is unspecified. AKK must resolve exactly one eligible Codex or Claude Code pane across all workspaces and use its currently advertised Send path. Managed delivery attaches or discovers its AKK session and verifies idle before input; Codex paginated physical Send does not require a managed Session and follows its terminal input-safety checks. If no eligible pane exists, report AKK's setup guidance; do not substitute another execution path.
On first attach, the target terminal must be explicitly named by the user; never guess which already-running pane should receive the task.
For ordinary send or an in-flight answer:
1. Reuse an AKK session only when the user's reference uniquely identifies its verified native session and terminal incarnation.
2. If no ID is supplied and more than one eligible pane may exist, call `agent_knock_knock_list`.
3. Treat `terminals[]` as the primary resource list. Its managed context exposes `session_id`; `managed.current_turn` is the only current AKK owner, while `managed.recent_turn` and `managed.history` are retained Turn history. Records in `unavailable_managed_turns[]` have no live pane in this snapshot.
4. Read the selected resource's `available_actions`. In the compact Host projection its keys are the exact current action names and each value is `true`; `action_inputs`, when present, carries only dynamic semantic arguments, `missing_required`, and scope. For every mutation, use only an advertised action, start with those semantic inputs, supply every `missing_required` field, and follow this skill's action rules. User-selected Watch is the exception: explicit user intent plus one complete exact `terminal_id` is sufficient even when `available_actions.watch` is absent. The only additional mutation sources are a terminal row's `handoff_decision.choices.take_over_current.action` and an exact `blocking_turns[].recovery_action`: use either only after explicit user confirmation and refresh the list immediately afterward.
5. If an existing managed Session advertises send with `session_id`, call `agent_knock_knock_send({session_id,request})`; it creates a new Turn strictly in that Session's native context and may require exact empty before input. If the selected row advertises terminal-scoped send, call `agent_knock_knock_send({terminal_id,request})`. `terminal_follow_current` may adopt a safe human-driven handoff or send once within an exact, complete Codex rollout-candidate inventory before binding the uniquely accepting native thread. `terminal_user_explicit` instead preserves the user's Send when internal AKK state is broken: Codex replaces the current Composer with `C-u`; Claude Code uses a sentinel-backed native `C-s` stash-clear transaction that is independent of the cursor position and does not interrupt an active turn, then proves the main Composer empty. Each injects the new request and submits exactly once without a post-text Composer veto. For source-less Codex sends, zero exact acceptors remains pending for monitor recovery, one promotes the provisional Session/Turn, and multiple acceptors or identity drift becomes uncertain without replay. Managed delivery is attempted where eligible, but a proven zero-input failure falls back to one unmanaged delivery with no managed callback Turn. AKK prepares the strongest safe Watch before dispatch and best-effort attaches it after Enter; Watch persistence failure never changes the successful Send. Once clear or request input may have occurred, an uncertain result must not be retried automatically. Wait for an attached Watch callback or use its status as recovery. The status-card-only first-task path remains the zero-rollout special case. `send({turn_id})` is never an ordinary target: use it only for a fresh `retry_submission` action after explicit confirmation, with no other field. Never construct or pass an opaque fence or composer authority. Use `respond` with its `turn_id` only when that Turn is explicitly `waiting_for_openclaw`; the answer stays in the same Turn. Do not add timeout fields for ordinary use; `timeoutSeconds` is unsupported.
6. If multiple terminals match, show their `short_ref`, agent, provider, and terminal target, then ask the user to choose. If a human switch has an unresolved Turn, ambiguous ownership, or unverifiable identity and no follow-current send is advertised, report that blocker and ask the user which context to resolve; never guess, supersede active work, or bypass the fence.
An idle pane is at a verified ready prompt, with no current work or unresolved permission request. A previously completed managed turn alone is not proof that the pane is still idle.
Do not treat ordinary Send's whole-draft Composer replacement as a native conversation clear, new-session, fork, branch, side thread, status probe, or resume. Do not send `/clear`, `/new`, `/resume`, `/status`, Codex `/fork`, `/side`, `/btw`, Claude `/branch`, or any other first-line native slash command as ordinary task or answer text. Dedicated native lifecycle and inspection tools own their closed commands, capability checks, serialization, identity verification, and binding fences; express other requests in natural language or leave unsupported native commands to a human in the terminal UI. Each successful lifecycle transition creates no Turn, and native inspection creates no Session or Turn.
## Terminal Watch
Terminal Watch follows the exact terminal selected by the user. Codex paginated exact Watch creation uses a closed `/status` transaction in an available main Composer to bind its foreground paginated task; subsequent observation is read-only. Answering a supported native interaction later is a separate explicit, owner-bound mutation. The normal sequence is user selects a Codex or Claude Code terminal → fresh `agent_knock_knock_list` or `/akk list` → copy its complete `terminal_id` and, when present, its advertised `watch` action → retain the returned `watch_id` for status or unwatch. Advertisement is discovery help, not Watch authorization. If the user explicitly supplies one complete exact terminal ID, call `agent_knock_knock_watch({terminal_id})` even when that row does not advertise Watch. Never infer a terminal or use a selector/short ID.
Managed ownership is not a veto. Prefer an existing managed Turn monitor when exact Turn attribution is wanted, but an explicit Watch may coexist because subsequent observation sends no input and does not adopt, replace, close, reserve, block, interrupt, approve, or otherwise mutate that Turn, Session, terminal, or task. Codex paginated exact Watch creation separately types the closed `/status` transaction described above. A successful `terminal_user_explicit` unmanaged fallback may separately return an automatic exact request-bound or terminal-activity Watch after AKK sends; retain that `watch_id` and use Status for recovery. Once exact request acceptance, terminal identity, owner, and one current supported native interaction are established, that Watch may emit an idempotent `interaction_required` callback. The callback itself is notification only; call `agent_knock_knock_status({watch_id})` in the owning controller conversation to obtain the single-use private response offer, and respond only when its projection says `capabilities.respond=true`. When exact response authority cannot be proven, AKK emits `interaction_manual_required` instead; that state and every terminal-activity Watch remain notify-only with `capabilities.interaction_respond=false`, so the human must answer in the live TUI.
At creation, AKK first tries to build a privacy-safe exact provider task anchor. A Codex paginated read-contract Watch binds the exact foreground thread and native task; older supported Codex versions bind rollout identity and request/turn byte boundaries. Claude binds transcript identity, root prompt, and current-turn byte boundaries. Success returns `watch_mode="exact_task"`, `confidence="exact"`. Legacy anchors invalidate on process, endpoint, native-thread, file identity, truncation/replacement, boundary, successor-task, or fingerprint drift. A Codex paginated Watch retains the original accepted native turn even when an unrelated later task starts; it never follows that later task or loses the original completion merely because a successor exists.
Missing or mismatched agent-version evidence is always a warning and does not weaken an otherwise usable exact task anchor. If no unique usable anchor can be established because artifact, native-task, or boundary evidence is unavailable or incompatible, do not reject. AKK records those diagnostics in `warnings` and creates `watch_mode="terminal_activity"`, `confidence="best_effort"`. Binding metadata, managed ownership, and missing action advertisement likewise remain non-veto warnings. This fallback follows only the selected terminal/process activity epoch. It must first observe `working` or `awaiting_approval`, then stable `idle` across consecutive supervision sweeps. Starting at `idle` or `unknown` never settles immediately; later activity must be observed first. For automatic fallback after Send, the Watch is request-correlated and starts with no observed activity: it must see activity after that Send, then two idle observations. Pre-Send activity cannot complete it. Replaying the same `message_id` cannot resend the task or create duplicate notifications.
Treat a terminal-activity completion-shaped callback exactly as labeled: it means the observed terminal activity became idle. It is not proof that one exact task completed or succeeded, and it carries no exact-task completion text. State that limitation plainly to the user. Do not silently upgrade it to managed or exact-task attribution.
Hard creation failure includes an absent exact terminal, inability to identify its endpoint/process, absence of both a durable exact-task anchor and a read-only screen-status activity path, inability to create/write the durable Watch Store, or uncertain native probe input. Safe read-contract failures may fall back to activity observation only after revalidating the physical endpoint, PID, process incarnation, working directory, and screen-status path; never bypass an unsafe input surface or retry uncertain probe input. Existing identical active observation may return its current `watch_id` instead of failing as a duplicate.
Approval attention is notification-only for every Watch: never call an approval tool for a `watch_id`, send approval keys, or apply `autoApprove`. Native-interaction attention is different. An automatic exact request-bound Watch created by `terminal_user_explicit` unmanaged fallback can, after exact request acceptance and attribution, emit `interaction_required`; call Status with its exact `watch_id`, show the projected question to the user, and use `respond_interaction({watch_id,...})` only when that fresh owner-bound projection advertises `capabilities.respond=true`. A terminal-activity Watch or `interaction_manual_required` callback remains notify-only: tell the user to inspect and answer in the live TUI, and send no interaction input. Each new exact attention fingerprint is notified once while the Watch remains active. Terminal outcomes settle once. The durable outbox uses deterministic notification IDs/idempotency and leased retry, so startup and periodic supervision can safely recover callback delivery after AKK, OpenClaw, or Gateway restart.
The current integrations register the complete capability-handshake-verified semantic AKK tool catalog and list action-contract v30. Structured OpenClaw, Pi, and DeepSeek Harness Lists use compact projection v1 and point here for the static contract; the CLI keeps the complete operator/debug action contract. Every structured model action carries semantic IDs only; opaque fences, Composer digests, and draft text are derived or retained privately. Watch uses `agent_knock_knock_watch({terminal_id})`, `agent_knock_knock_status({watch_id})`, and `agent_knock_knock_unwatch({watch_id})`; its internal CLI boundary is `watch-terminal`, `watch-status`, `unwatch-terminal`, and `reconcile-watches`.
For Codex permission changes, first call `agent_knock_knock_permission_options({terminal_id})` from the current row’s advertised action. This sends closed `/status` and `/permissions` inspection input but leaves permissions unchanged; the terminal must be idle, its Composer empty, and its physical and native thread identities verifiable. Use `current`, `scope`, and the returned choice descriptions to select the requested or authorized mode. Then call `agent_knock_knock_set_permissions({terminal_id,mode})` using its exact returned semantic ID in the same controller conversation. Full Access is an ordinary option and needs no additional user confirmation. AKK automatically handles its exact native confirmation inside this permission transaction; do not pause to ask the user to confirm Full Access or call generic `approve` for that dialog. Ordinary Send does not change permissions. Only currently displayed built-in modes are supported: do not invent `read_only` when the picker omits it, supply a named/custom profile, or pass commands, labels, menu indexes, keys, tokens, or scope overrides. Changes affect the current session/thread, may be retained on Resume, and leave global defaults unchanged. Send the intended task only after `outcome="changed"` or `"already_effective"` with matching `effective.mode`; `"uncertain"` means stop and do not retry automatically. Refresh the catalog after any change or consumed attempt.
For native model control, first call `agent_knock_knock_model_options({terminal_id})` only from the current terminal row's advertised action. This is explicit current-snapshot authority for one exact physical pane/process: Profiled Codex 0.154.0/0.155.1 may use either one exact current native Session or a verified-zero-rollout pane, where `identify_foreground` is diagnostic rather than a prerequisite; Claude Code still requires one exact current native Session. The pane must have no active Turn, approval, questionnaire/editor, or read-only viewer. It normally requires an idle empty Composer; when List advertises `model_options` for one exact stable profiled Codex 0.154.0/0.155.1 `/model` residual, AKK may continue only that residual into read-only catalog discovery. Show the returned `scope`, current selection, and semantic model/effort catalog to the user. Then call `agent_knock_knock_set_model({terminal_id,model,reasoning_effort})` with an exact required tuple from that same result in the same controller conversation. Codex scope is always `current_and_new_sessions`: a successful selection persists the model and an ordinary effort (including `max`) for future sessions, but `ultra` is current-session-only and Codex chooses a non-Ultra future fallback. Always read `effective` and `new_session_defaults` separately. Claude Code scope is always `current_session`. There is no caller-selectable scope. Never pass a display label, menu index, slash command, raw key, token, or fingerprint. A stale or consumed catalog must be refreshed, and `outcome="uncertain"` must never be retried automatically.
If the current List also advertises `repair_model_control`, it is the explicit
cleanup-only alternative: call
`agent_knock_knock_repair_model_control({terminal_id})` or the matching
`/akk repair-model-control <exact-terminal-id>` only when the user wants the
residual cleared instead of continuing discovery. For an already-open exact
native picker this is the only model-control action List may advertise: it may
dismiss the picker but has no Enter authority. It accepts no raw text or keys,
never presses Enter, and must prove an empty Composer. Refresh List after
success; never retry an uncertain repair automatically.
For native status inspection:
1. Use only a current `available_actions.native_inspect({terminal_id,inspection:"status"})` entry. Those semantic arguments are complete; never add a command or authority field.
2. Regression-tested profiles are Codex 0.146.0/0.146.1/0.147.0/0.148.0/0.149.1/0.150.1/0.151.0/0.153.0/0.153.4/0.154.0/0.155.1/0.158.0/0.159.0/0.159.2 and Claude Code 2.1.218/2.1.226/2.1.237/2.1.251/2.1.259/2.1.263/2.1.266/2.1.267/2.1.285 `inspection="status"`. Other complete `x.y.z` versions remain callable through the generic runtime profile and add a compatibility warning; actual incompatible UI or schema evidence fails at runtime and is not automatically retried. Claude success includes parsing and safely dismissing the newly opened Status panel. The inspection tool does not accept `/status` text or any arbitrary command string. `/usage`, `/cost`, `/stats`, `/usage-credits`, raw `/model`, `/compact`, and arbitrary slash commands remain unavailable; model changes use only the typed model-control tools above. Never automate bare Codex `/usage`: it opens an interactive menu whose later Enter can select an account-side usage-limit reset.
3. Treat this as terminal input even though the native command is read-only. AKK privately derives a fresh binding fence and requires an idle empty composer, exact PID/process/pane/cwd/version identity, and no conflicting Turn, transition, dispatch, approval, or owner.
4. Codex `/status` requires an exact viewport of at least 80 columns so the full Session UUID can be proven. That pre-UUID gate applies to native inspection, lifecycle, and strict Session operations that must know the UUID before terminal input. Legacy terminal-scoped ordinary tasks may send once and bind from exact native acceptance afterward without running `/status` or failing merely because the pane is narrow. Codex paginated read-contract candidates attempt their separate closed `/status` binding before physical Send. If an exact callback Watch cannot be prepared safely, AKK may prepare terminal-activity observation; report the receipt's actual callback mode and limitation.
5. The result is valid only when AKK proves one fresh bounded native status result and the pane returns to idle. On an uncertain or unproven submission, do not retry, send Enter, clear the composer, or bypass AKK with raw terminal input.
6. Native inspection creates no AKK Session, Turn, receipt, monitor, callback, or response round.
For native-thread lifecycle discovery or mutation:
1. Start from the exact terminal row's currently advertised `list_resumable_threads({terminal_id})` or `new_thread({terminal_id})` action. Listing is read-only and creates no Turn.
2. Before `new_thread` or `resume_thread`, the terminal must be verified idle and have no active or unresolved Turn. The plugin/CLI derives and revalidates the current binding fence internally; the model never supplies one.
3. For resume, list candidates first and invoke only `resume_thread({terminal_id,native_thread_id})` for one row with `resumable=true`, using its complete UUID. Never select by title, preview, recency, or partial UUID. Human slash-command numbers and collision-safe short IDs refer only to the current private snapshot and are resolved inside AKK; they are never structured tool arguments. If the user says “previous” or “刚才那个”, proceed only when AKK advertises one exact previous candidate derived from the latest committed transition; if absent, explain that AKK cannot prove it and ask the user to list/select instead.
4. Treat mutation success as a Session/native-context transition, not as task delivery. It creates or activates an AKK `session_id`, advances the terminal binding generation, and creates no `turn_id`. The next ordinary send creates the first Turn in that context.
5. If the agent/version is unsupported, a candidate is ambiguous or active elsewhere, the private fence is stale, or post-transition identity cannot be verified, fail closed and report the error. Do not fall back to raw terminal commands.
Useful examples:
```text
/akk review the current branch and propose a small fix
/akk codex: inspect the repository and summarize it
/akk @a1b2c3d4: run the focused tests
/akk list
/akk threads terminal:v2:tmux:codex:akk-work:0.0:1234
/akk models terminal:v2:tmux:codex:akk-work:0.0:1234
/akk set-model terminal:v2:tmux:codex:akk-work:0.0:1234 gpt-6-astra ultra
/akk new-thread terminal:v2:tmux:codex:akk-work:0.0:1234
/akk resume-thread terminal:v2:tmux:codex:akk-work:0.0:1234 previous
/akk resume-thread terminal:v2:tmux:codex:akk-work:0.0:1234 2
/akk resume-thread terminal:v2:tmux:codex:akk-work:0.0:1234 11111111-1111-4111-8111-111111111111
/akk status only
/akk respond @a1b2c3d4: use the existing JSON format
/akk cancel only
```
## Terminal Communication Contract
All controller-to-agent task delivery must go through Agent Knock Knock plugin tools. Do not use Host-internal session tools, raw terminal-provider commands, shell commands, or another messaging path to bypass AKK's terminal checks.
AKK:
1. Resolves the authoritative AKK session to its selected Codex or Claude Code native session, process, and terminal pane.
2. Revalidates the expected agent PID and provider-owned terminal identity, confirms that the process and pane working directories match, and verifies the idle prompt.
3. Types only the user-facing task into the shared terminal.
4. Creates a unique managed `turn_id` bound to the AKK `session_id`, terminal incarnation, and message.
5. Monitors reliable local evidence and sends callbacks to the originating controller session.
The coding agent does not run an AKK callback command and does not require an AKK-specific hook or plugin.
After an asynchronous send operation is accepted, end the controller turn. Wait for AKK's callback unless the user explicitly requests status.
## Status
For managed terminal entries, `agent_knock_knock_status` captures AKK Turn state plus a bounded terminal screen and returns `terminal_screen`. With `watch_id`, it returns the exact durable Terminal Watch record, including `watch_mode`, `confidence`, and any warnings. It must not imply that an exact task completed when a `terminal_activity` Watch only observed stable idle, or that Watch sent/adopted the task. Neither form actively executes the coding agent's native `/status`. Use `agent_knock_knock_native_inspect` only for a terminal row's advertised, version-scoped native status action. Do not inspect the pane with raw provider or shell commands unless the relevant AKK inspection is unavailable or fails.
For an exact managed Turn or a response-capable exact Watch, Status may return a native `interaction_state`. The managed monitor or exact Watch proactively sends an `interaction_required` callback for each supported actionable step, but that callback is notification only: it does not create response authority. In the owning controller conversation, call Status with the callback's exact `turn_id` or `watch_id`, treat the returned state as a single-use current-step projection rather than ordinary response text, and display it to the user. The private response offer exists only in the same controller conversation that displayed that Status result. Require `state="pending"` and `capabilities.respond=true`, review the projected question with the user, and pass exactly the same subject id plus only its semantic ids and typed answer to `agent_knock_knock_respond_interaction`. A blocking `questionnaire` may pause the task and never advertises or accepts `delivery_mode`. A Codex `async_question` coexists with a still-`working` task, advertises `delivery_modes`, and defaults to advertised `steer_current_turn`; explicitly select advertised `queue_next_turn` to queue the response. For an async-question custom answer, select its advertised native Other option and refresh Status for a separate `free_text` step; this does not use blocking Notes. For a blocking Codex questionnaire custom answer, choose the guarded `Type something.` option advertised beside the exact client-generated `None of the above` row; AKK derives this semantic option when the client rendered only native Other. AKK moves to that native Other row, opens its Notes editor, and the next fresh interaction accepts `free_text`; choosing `None of the above` itself still submits it directly without Notes. Codex delivers custom text as `user_note: ...` alongside the native Other label, not as a Claude-style bare value. One call answers one step; wait for the next callback or refresh Status after success because the next question, custom-text editor, or final confirmation has a new `interaction_id`. If only the displayed `expires_at` has elapsed while its session-bound private offer remains live, Respond performs an exact locked terminal recapture before input; changed, missing, `manual_required`, secret, multi-select, uncertain, terminal-activity, or subject-mismatched interactions still fail closed. Codex 0.154.0 and 0.155.1 use version-bound native TUI evidence for async questions; do not assume either release contains the notification or stable-question-identity wrappers added only on post-0.155.1 main. Never send raw keys, shortcut chords, or menu indexes, and never retry blindly.
## Cancellation and Recovery
`agent_knock_knock_cancel` uses the adapter's interrupt action—Control-C for Codex or Escape for Claude Code—and leaves the terminal pane open.
Use `agent_knock_knock_renew` only when AKK marked the same live terminal Turn `stalled`, the process and Turn remain in the same pane, and the user wants monitoring to continue without terminal input. The contextual slash form is `/akk renew @a1b2c3d4 30`.
Use `agent_knock_knock_retry_callback` only for a `callback_failed` managed turn, for example `/akk retry-callback @a1b2c3d4`.
Submission retry remains part of `agent_knock_knock_send`, not callback retry or renewal. Use its exact `{turn_id}` form only from a current advertised `retry_submission` action and only after explicit confirmation. AKK never accepts replacement text from the caller, never clears the composer, and never sends Control-C. It first checks for native acceptance and repairs state without input when possible. Otherwise it fails closed unless it can prove the exact existing draft for one Enter, or prove both that Enter was never attempted and that the live composer is positively empty before retransmitting the immutable original request once. Any terminal, identity, route, draft, modal, approval, working-state, or one-shot reservation drift sends no further input.
Use `agent_knock_knock_close` only after the user explicitly asks to close the selected AKK Turn. That explicit choice has priority over stalled, deferred-transfer, Session, ledger, handoff, callback, or receipt conflicts: Close first records the Turn as closed and releases AKK management. It never sends terminal input, interrupts or stops the coding agent, or closes the terminal pane. Cleanup of linked AKK transfer, Session, ledger, and callback metadata is best-effort; preserve stale, malformed, or newer records and report warnings instead of refusing the user's Close. A callback attempt already in flight or accepted by the host may still arrive, but Close authorizes no new callback start or retry. Refresh `agent_knock_knock_list` afterward; if the coding agent is still working, explicitly Watch its exact `terminal_id` whether or not that row advertises the convenience action. Orphan terminal-dispatch/lifecycle recovery with `expected_message_id` or `expected_transition_id` remains a separate raw-terminal operation.
Use `/akk doctor` only for installation checks or troubleshooting.
## Terminal Approval
Approval is a sensitive action. On an unmanaged raw-terminal row, the terminal-scoped Codex approval action is prefilled with its exact `terminal_id`; never construct or guess that target.
A Terminal Watch approval callback is not an approval action. Notify the user and require them to inspect and decide in the live TUI; never continue with the steps below for a `watch_id`.
1. Call `agent_knock_knock_status`.
2. Show the detected request details to the user.
3. Require the user to explicitly choose one exact semantic decision advertised for that request: `approve_once` or, when present, `reject`.
4. For a managed Turn, call only the current advertised `approve({turn_id,decision})`. A terminal-scoped action supports `approve({terminal_id})` / `approve_once` only. Do not add a raw key, menu index, rendered label, token, or fingerprint.
AKK retains a private confirmation offer, then recaptures and revalidates the exact prompt, process, pane, owner, and decision under lock immediately before one approval key. If anything changed, the action fails closed and requires a fresh review.
For hookless Claude Code, the callback intentionally omits the raw command. Require the user to inspect the named live terminal pane personally; never decide from a hash or summary alone. Claude manual approval always permits only a strictly recognized one-time **Yes** choice and may additionally advertise semantic `reject` only when the exact supported menu proves a native **No** row. Codex approval likewise requires the current visible prompt and advertises `reject` only for an exact safe native rejection choice. A terminal-scoped Codex approval is manual-only, approve-once-only, carries `terminal_id`, leaves managed identity unchanged, and must not be retried blindly after an uncertain transport result.
Unknown, stale, expired, ambiguous, persistent-permission, replayed, or changed requests must not receive any decision key. If semantic `reject` is not advertised, tell the user to resolve the prompt directly in the terminal; use `agent_knock_knock_cancel` only when the user explicitly intends to interrupt the whole Turn, never as a disguised No choice.
A trusted, default-disabled plugin `autoApprove` policy may independently approve only an exact configured agent, command vector, and canonical root listed in `autoApprove.rules[].workspaces`, backed by current terminal evidence. A rule may list multiple workspace roots. These entries are the only workspace boundary for automatic approval; they do not limit pane discovery or manual control. The model cannot create or modify that policy.
## Terminal Sessions
`agent_knock_knock_list` is terminal-first: every eligible already-running Codex or Claude Code pane appears once in `terminals[]`, even when retained managed Turns reference it. The resource chain is terminal → verified native session → managed AKK `session_id` → Turns; independent observation-only records appear in `terminal_watches[]` and are addressed only by `watch_id`. `process_state` reports process liveness. Read `screen_state` as bounded live-TUI evidence, `native_identity_state` as foreground native-session resolution, and `durable_activity_state` as exact artifact-backed task activity. The legacy `activity_state` is a conservative compatibility projection and may remain `unknown` while `screen_state="idle"`; none of these diagnostic fields replaces `available_actions` authority. `managed.current_turn` is the authoritative active Turn for that terminal; otherwise `managed.recent_turn` shows the newest retained context. A human-driven thread mismatch remains `management_state="conflict"`; `handoff_state="external_handoff_adoptable"` authorizes only the exact fenced `send` advertised on that row, while `external_handoff_blocked` means do not send or guess a recovery. Listing itself never adopts the new context. Request `all=true` only when older `managed.history`, settled Terminal Watches, or retained unavailable history is needed. By default, `unavailable_managed_turns[]` contains attention-needed records whose terminal is unavailable.
### Compact controller-Host List projection
The structured OpenClaw, Pi, and DeepSeek Harness tools return `projection.schema="agent-knock-knock/host-list-compact"`, `projection.version=1`, `projection.skill="agent-knock-knock"`, and the CLI action-contract version. They deliberately omit the repeated 30KB static `action_contracts`, explanatory `reason`/`use` text, Store paths, terminal diagnostics, native evidence, callback envelopes, full historical requests, completion text, screens, and event/file paths. Use Status for one selected Turn or Watch and `/akk doctor` or the CLI for operator diagnostics. A bounded dynamic failure `message` or scan `error` may still appear because it cannot be documented statically.
For every resource, `available_actions` is an object whose keys are the exact current semantic action names and whose values are `true`. `action_inputs` contains only dynamic semantic values that cannot be derived from the parent resource, plus scope, permitted decision values, and fields listed by `missing_required`; it does not repeat the same terminal/Session/Turn/Watch ID for every action. The parent terminal `id` is the full `terminal_id`; managed and Watch records expose their own `session_id`, `turn_id`, or `watch_id`. `features` is only a compact capability-status summary and never authorizes an action. Never infer an absent action. The compact display is not the enforcement boundary: the plugin caches the complete private offer before projection, and the CLI re-observes and revalidates the live pane under its action lock before every mutation.
Action-name glossary:
- `status`: inspect one terminal, Turn, or Watch; it sends no native slash command.
- `send`: deliver a new request, or perform the separately advertised immutable `retry_submission` form.
- `watch` / `unwatch`: create or stop durable terminal observation; Codex 0.158.0/0.159.0/0.159.2 exact creation performs the closed `/status` transaction, while subsequent observation is read-only.
- `list_resumable_threads`, `new_thread`, and `resume_thread`: inspect or change native thread context through their closed lifecycle protocols.
- `native_inspect`: run only an advertised closed native inspection such as `status`.
- `model_options`, `repair_model_control`, and `set_model`: discover the current native catalog, clear only a proven model-control residue, or consume one catalog offer.
- `permission_options` and `set_permissions`: inspect one idle Codex pane’s built-in permission modes, then consume one catalog for the requested or authorized change, including Full Access without an extra confirmation. Ordinary Send never increases permissions.
- `identify_foreground` / `identify_and_send`: diagnose Codex foreground identity, or keep that diagnosis and one Send atomic.
- `reconcile_binding`: detach only the exact listed stale/conflicting AKK binding after explicit user confirmation.
- `respond`: answer ordinary text inside the current managed Turn.
- `respond_interaction`: answer one current native interaction step obtained from fresh Status; an `async_question` defaults to advertised `steer_current_turn` or accepts explicit advertised `queue_next_turn` as `delivery_mode`, while a blocking `questionnaire` omits it.
- `approve`: apply only an explicitly confirmed advertised semantic approval decision.
- `cancel`: interrupt the selected active Turn without closing the terminal.
- `renew`: extend monitoring for an eligible stalled Turn without terminal input.
- `retry_callback`: retry delivery of an eligible failed callback without terminal input.
- `close`: release AKK management for the selected Turn without stopping the coding agent or closing the pane.
The tool name is normally `agent_knock_knock_<action-name>`. The sole List alias is `retry_submission`, which invokes `agent_knock_knock_send` with its listed `turn_id` only after explicit confirmation. Nested `handoff_decision.choices.take_over_current.action` and `blocking_turns[].recovery_action` carry their explicit tool/action name and semantic arguments; the explanatory choice and recovery text is defined here rather than repeated in every List row.
`available_actions` is the authoritative current-action source for mutations after listing except for the explicitly modeled nested handoff decision and `blocking_turns[].recovery_action`; user-selected `watch({terminal_id})` deliberately honors an exact user-selected terminal even without advertisement. A native interaction response instead requires the current `interaction_state` returned by Status in the same controller conversation. Approval, native interaction response, handoff takeover, and `reconcile_binding` require explicit user intent and fresh source state. Model-facing shapes include `permission_options({terminal_id})` and `set_permissions({terminal_id,mode})`; `model_options({terminal_id})`, the separately advertised Codex-only `repair_model_control({terminal_id})`, and `set_model({terminal_id,model,reasoning_effort})`; `watch({terminal_id})`; `send({session_id|terminal_id,request})`, with the targets mutually exclusive; `identify_foreground({terminal_id})`; `identify_and_send({terminal_id,request})`; `respond_interaction({turn_id|watch_id,interaction_id,answers,delivery_mode?})`, with exactly one subject id, only projected question/option ids, and `delivery_mode` present only for `async_question`; managed `approve({turn_id,decision})` or approve-once-only terminal-scoped `approve({terminal_id})`; `native_inspect({terminal_id,inspection})`; `new_thread({terminal_id})`; `resume_thread({terminal_id,native_thread_id})`; and `reconcile_binding({terminal_id,conflicting_session_id})`. A top-level `previous` block, when present, is the only authority for a “previous/刚才那个” request; human-facing numbers and short IDs remain slash-navigation aids and are never structured tool arguments. The model never carries terminal, binding, catalog, candidate, composer, handoff, approval, interaction-fingerprint, revision, binding ID/generation, or handoff-only live-native-UUID fences; it never receives draft text or composer digests. `native_thread_id` remains the semantic resume identity. AKK derives those private fences and revalidates them before side effects. Orphan-close `expected_message_id` and `expected_transition_id` remain because they are entity IDs. Store format remains 1 and writer protocol is 9; Terminal Watch schema remains 3.
Before every terminal operation, AKK revalidates the expected agent PID and provider-owned terminal identity. Native inspection and lifecycle input require an exactly empty Composer; managed Send may require exact empty before input. Codex and Claude Code `terminal_user_explicit` instead require a scanned non-blocked approval state and no proven input-owning questionnaire, editor, menu, or read-only viewer. Reviewed physical Send paths do not require ordinary main-Composer visibility, stability, or exactness. Unreviewed Codex frontends require a recognized styled Composer before clearing and a fresh empty styled Composer before task text. Existing drafts and parsed working activity do not themselves veto the user-priority path, and after text injection no Composer observation may veto Enter. Once clear or request input may have occurred, an uncertain result must not be retried automatically. Humans can attach to the same tmux or Herdr session and continue directly at any time.
Exact-task Claude Code completion depends on a strictly correlated local transcript turn and fails closed for unknown schemas, background work, or ambiguous identity. A `terminal_activity` Watch may separately notify that the selected terminal became stably idle only after observed activity; always label that callback best-effort and never report it as exact task completion or success.
## Final User Reply
Do not replay internal terminal-monitor or callback details.
Return:
- what was delivered;
- important files or behavior changed;
- verification performed;
- remaining issues, if any; or
- the actionable failure reason.