Harness integration
UHP and Claude Code
HarnessRouter lists Claude Code as a released backend and the UHP specification uses claude-code as an example stable base string. Current HarnessRouter v0.18.4 support remains adapter evidence, not native UHP adoption or endorsement by Anthropic.
Verified relationship
Section titled “Verified relationship”HarnessRouter Community Edition lists Claude Code as a supported harness backend and the UHP specification uses claude-code as an example stable base string. Current HarnessRouter stable and checked main are v0.18.4 / efd320b313891191967871de28ff4757528ae6a7 at this cutoff. The releases since the previous v0.16.1 cutoff change broader provider, routing, connection, conformance and self-host behavior rather than establishing a new Claude-specific adapter contract; they do not establish native UHP adoption by Claude Code.
In the UHP model, the product does not need to speak a Claude Code-specific product integration. It targets a configured harness through the UHP server. The server is responsible for driving the actual backend and translating its execution into UHP tasks, sessions, events, artifacts and errors.
What UHP tries to normalize
Section titled “What UHP tries to normalize”- Task submission and terminal status.
- Progress streaming.
- Session continuation.
- Files and artifacts where supported by the conformance class.
- Cancellation behavior.
- Structured errors and capability discovery.
HarnessRouter integration note: plugins and stdio MCP are released
Section titled “HarnessRouter integration note: plugins and stdio MCP are released”HarnessRouter v0.9.0, released 24 August 2026, ships the Claude Code plugin work that this page previously described as unreleased. A configured harness can carry Claude Code plugins containing commands, hooks, subagents and a plugin-owned MCP server over stdio. HarnessRouter materializes the plugin for the turn and passes it to Claude Code with --plugin-dir; its runner also emits stdio MCP servers in addition to HTTP and SSE MCP transports.
That is a HarnessRouter implementation feature around Claude Code. It does not mean Anthropic changed Claude Code to speak UHP, and it should not be presented as native UHP support by Claude Code.
Current upstream Claude Code: composition, host visibility and execution boundaries
Section titled “Current upstream Claude Code: composition, host visibility and execution boundaries”The latest observed upstream Claude Code release is v2.1.277, published 18 September 2026 at 18:06:32 UTC, tag commit ca02e7deeb0707f558b0afd7e9e5d67a382e12b3. PR #95409’s agents-md built-in mod merged immediately before that release as a92ea1cdb11ad21f9d583fad2db181dfdac918a6, and the published 2.1.277 changelog explicitly advertises AGENTS.md support. Checked upstream main is now 6ce37e9f464cf75d172754ba70a42e01c3d876e9. Its material post-release change for this page is PR #95417 / 2fc72b2918b43710ff4c7c73be173100c2cbe379, which aligns nested AGENTS.md attachment behavior with runs where Claude Code’s engine is configured to attach no instruction/context files to a turn. The following 6ce37e9f commit is an unrelated diff mod typing fix. Stable release semantics remain v2.1.277 / ca02e7de; the PR #95417 correction is current-main behavior after that tag.
The current line retains the peer-session and restricted-execution architecture introduced in v2.1.248 while extending unattended-host policy, managed MCP configuration, subagent durability, SDK/headless integration, resume fidelity, host-side safety and repository-instruction interoperability.
Cross-session messaging
Section titled “Cross-session messaging”Claude Code 2.1.248 expands same-machine cross-session messaging through SendMessage and ListAgents to Bedrock, Vertex, Foundry and environments where telemetry is disabled. The same release also validates the crossSessionInbound setting instead of silently accepting invalid values, and clarifies that a message sent from a subagent to another session routes any reply back to the parent session’s conversation.
This is another concrete harness-composition pattern: independent Claude Code sessions can coordinate directly on one machine while retaining separate session state. It is upstream Claude Code behavior, not a UHP primitive. If Claude Code is running behind a UHP server, those internal peer-session messages do not become additional UHP tasks or sessions unless an implementation explicitly maps them that way.
Restricted mode
Section titled “Restricted mode”The same 2.1.248 release adds --restricted / CLAUDE_CODE_RESTRICTED=1. In that mode Claude Code removes built-in command/code execution tools and WebFetch unless explicitly named in --tools, constrains file tools to the working directory, refuses bypassPermissions, and ignores user, project and local settings files.
That is relevant to harness isolation and policy design, but it remains a Claude Code runtime control. UHP 2026-09-12 does not require this flag or define its semantics, and HarnessRouter support for Claude Code does not imply that every configured UHP harness uses restricted mode.
2.1.251: subagent visibility and coordination hardening
Section titled “2.1.251: subagent visibility and coordination hardening”Claude Code 2.1.251 makes foreground-subagent activity more observable to a host: Remote Control clients can now receive the foreground subagent’s tool calls and results live, while background subagents continue to expose status rather than their full tool stream. The release also fixes several coordination failures: an agent-team teammate’s final answer now reaches the team lead, background subagents can reply to unnamed sibling or parent agents, and SendMessage replies to messages delivered from another session can route through Claude Desktop instead of failing as unreachable.
The same release changes CLAUDE_CODE_SUBAGENT_MODEL from an unconditional override to a default. An agent definition’s model: value or an explicit model chosen when spawning a child takes precedence. That is a meaningful specialization control for composed-agent topologies, but it remains internal Claude Code configuration rather than a UHP model-selection rule.
Adapter-facing stream and MCP reliability
Section titled “Adapter-facing stream and MCP reliability”2.1.251 also fixes a concrete headless integration edge: with --input-format stream-json, client-injected assistant tool calls that arrive without a message id are no longer merged into the first call with later tool results lost, including when resuming older sessions. Separately, an SDK MCP server whose handshake acknowledgement is lost now times out after 70 seconds and isolates the failure to that server instead of hanging the SDK/cloud session indefinitely.
These changes improve upstream adapter reliability. They do not establish that Claude Code’s Remote Control/subagent stream, MCP lifecycle or internal session graph is exposed as additional UHP primitives.
2.1.257–2.1.261: unattended hosts, MCP policy and composition durability
Section titled “2.1.257–2.1.261: unattended hosts, MCP policy and composition durability”The later stable line adds several controls that are directly relevant when Claude Code is embedded inside a larger agent system.
Claude Code 2.1.257 adds a Containment Escape rule to auto mode so cloud metadata-credential fetches, egress evasion and cross-tenant reach are not auto-approved unless the environment marks them expected. It also adds CLAUDE_CODE_SUBAGENT_MODEL_FORCE, which can deliberately override per-spawn and agent-definition model selection for every child. These are Claude-specific authorization and composition controls rather than portable UHP policy or model-routing fields.
Claude Code 2.1.259 adds managed managedMcpServers configuration for organization-provided HTTP/SSE MCP servers and --permission-prompts none for unattended headless hosts, where an action that would require a prompt is denied automatically while the selected permission mode continues to decide what can run without prompting. The same release fixes concurrent sessions reverting one another’s ~/.claude.json state, reports MCP servers that disconnect during startup tool listing as failed rather than falsely connected-with-no-tools, keeps nested background-subagent results in the parent subagent transcript, and resumes remote/scheduled sessions after a connector-tool permission prompt is approved.
Claude Code 2.1.260 then strengthens the active headless/composed path again. /reload-plugins is available to headless sessions, including Desktop and Agent SDK command surfaces; SDK-provided MCP servers that could be absent from the first turn are now available on that first turn; -p --resume / --continue can recover after a worktree loses its Git metadata instead of failing every retry; a subagent that resumed another agent via SendMessage is woken by that agent’s completion; agent-team transcripts no longer lose real messages during long API retry waits; and background sessions no longer produce a duplicate interactive twin in ListAgents.
The release also prevents Workflow subagents from being restarted as stalled while a long context compaction is still in progress and removes the previous one-hour limit on background commands started by subagents. Those changes matter to long-running composition because a host should not mistake compaction latency for child death or impose a different background-command lifetime merely because work was delegated.
Claude Code 2.1.261 adds another integration-focused layer. Hosts can raise bashOutputMaxChars and taskOutputMaxChars so command/background-task output stays inline up to 128K characters before spilling to a file, and --append-subagent-system-prompt-file lets large child-system prompts come from a file instead of a command-line argument. Resumed sessions now preserve hook output and surrounding context across parallel tool calls instead of changing the resumed request. SDK/cloud sessions honor a Stop or interrupt sent immediately after the first prompt even if the turn has not started yet, failed background-agent resumes no longer spin in a tight wake-up loop, and terminal progress state no longer reports completion while a background workflow or agent is still running.
The same release also tightens coordination fidelity: SendMessage to an offline Remote Control session now reports the message as queued until that machine reconnects instead of falsely reporting delivery, and in-process agent-team teammates no longer resend their first-turn tool/skill announcements on turn two, which had changed the request prefix and missed the prompt cache. These are concrete host/composition semantics, not UHP task-state, delivery or prompt-cache rules.
2.1.265–2.1.268: continuity, MCP/tool stability and host-side safety
Section titled “2.1.265–2.1.268: continuity, MCP/tool stability and host-side safety”Claude Code 2.1.265 adds several material runtime corrections for harness hosts and composed-agent systems:
- Resume fidelity after interruption: if the previous Claude Code process died while a tool was running, resume no longer rewrites the last prompt; the interrupted tool call is retained and marked interrupted.
- Workflow restart finality: after a workflow container restart, a missing run journal now causes a clear resume failure instead of rerunning every agent. This prevents missing durable state from being mistaken for a valid replayable workflow.
- Subagent prompt stability: foreground-resumed subagents retain their tool list/system-prompt prefix, and teammates/resumed subagents keep
SubagentStarthook context and preloaded skills in the prompt prefix on later turns, preserving prompt-cache identity. - Background lifetime: a
--bgsession is no longer retired mid-turn merely because a message arrives just before the idle timeout. - Headless shell state: non-interactive
-pstream-json, Agent SDK and cloud sessions no longer reset shell working directory on each user message; acdpersists across turns. - MCP transport compatibility: an MCP server configured as
httpbut speaking legacy HTTP+SSE can now fall back to SSE rather than never connecting. Remote MCP servers that require sign-in also defer OAuth client registration until authentication is actually requested. - Plugin path containment: on macOS/Linux, a backslash in a plugin path can no longer bypass the symlink containment check. Uncheckable default component folders such as symlink loops are reported instead of silently skipped.
- Git probe side effects: Claude Code’s own
git status/git diffprobes no longer execute clean filters configured by a nested repository inside the working tree. - Connector/tool declaration fidelity: artifact publish refuses when none of a connector’s declared tool names actually exist and warns on partial mismatches instead of accepting an impossible tool surface.
- Stream visibility: forked skills using
context: forknow stream their kickoff prompt and, with--forward-subagent-text, their text turns as progress events instream-json.
Claude Code 2.1.266 immediately fixes one 2.1.265 regression for LLM-gateway and proxy deployments. CLAUDE_CODE_USE_GATEWAY by itself had begun forcing Cloud-gateway sign-in, breaking configurations that used it alongside an API key, apiKeyHelper or custom auth headers. The variable alone is ignored again; Anthropic’s changelog says no configuration change is required.
Claude Code 2.1.267 then adds several host-facing controls and continuity fixes that are material when the harness is embedded or resumed:
- Provider-wide effort ceiling:
maxEffortLevelcan cap effort globally or per model, including Bedrock, Vertex and Foundry, while allowing a lower user-selected level. - Prompt-snapshot control:
--system-prompt-snapshot offrenders the system prompt fresh for every request instead of replaying the conversation’s recorded prompt, explicitly supporting prompt iteration. - Large-resume fidelity: resumed transcripts larger than 5 MB no longer lose parallel tool calls or their hook output;
-p --resumeafter a slash command also no longer inserts a synthetic “Continue from where you left off.” turn. - Fail-closed managed allowlists: unreadable
allowedHttpHookUrls,httpHookAllowedEnvVarsandallowedChannelPluginsnow admit nothing rather than everything. - Dynamic MCP/tool continuity: a tool disappearing mid-conversation or reconnecting at a different time no longer rewrites earlier tool state in ways that drop reasoning; resumed sessions replay recorded tool descriptions/announcements rather than reconstructing them opportunistically, and supported sessions without ToolSearch receive mid-session MCP/plugin tools as deferred definitions.
- Prompt-cache stability: model switches, resumed MCP connector timing, print-mode-to-interactive resume, and subagents/sessions created with system-prompt overrides avoid unnecessary prompt-prefix/tool-definition rewrites that previously caused cache misses or could discard extended thinking.
- Remote-host durability:
claude remote-controlre-registers when its long-lived server credential expires instead of exiting and dropping attached sessions. - Containment and delivery: fetched marketplace paths containing backslashes can no longer bypass containment on macOS/Linux, and interrupted artifact uploads retry once when Claude Code can establish that the upload never completed.
Claude Code 2.1.268 is a broad host/integration hardening release with several changes directly relevant to embedded harness operation:
- Gateway boundary controls: gateways warn when
access_control.allow_cidrsis empty and on the first public-address request, whilegatewayInternalNetworkslets administrators allow gateway login from an organization’s own public IPv4 range. Gateway pricing can also be distributed through managed settings so signed-in clients report costs against the same rates. - Self-hosted session hygiene:
claude self-hosted-runner --remove-session-statecan delete each session’s per-session directory at session end; it is off by default. - Third-party endpoint compatibility: the release fixes the Artifact input-schema regression that caused every turn to fail with HTTP 400 on some
ANTHROPIC_BASE_URLcompatible endpoints since2.1.265. - MCP authentication and secrecy: MCP tool-call continuation no longer sometimes produces an empty-message reply;
${VAR}-resolved secrets are no longer exposed by/mcp,/plugin,claude mcp list/getor MCP login errors; and OAuth sign-in no longer fails solely because the local callback port range cannot be bound. - Headless/plugin automation: plugin install, uninstall, update, enable and disable gain
--json;PermissionRequesthooks now fire in--printmode; policy-helper warnings print in headless runs; and plugin install/enable/disable changes apply when the menu closes without requiring/reload-plugins. - Prompt and tool-list stability: SDK sessions using
excludeDynamicSectionsstop re-rendering the first message each request, preserving prompt caching and extended thinking; Bedrock, Vertex and Foundry now keep the tool list byte-stable across a conversation by deferring late-connecting tools rather than rewriting it. - Resume and permission fidelity:
--continue/--resumesurfaces the conversation before SessionStart hooks finish and avoids rereading the whole transcript for the first message; deny/ask rules now apply consistently across symlinked directory spellings and remain effective when an unanalyzable shell construct such asenv -Corevalis on the same line.
These are upstream Claude Code runtime/security/transport semantics. They do not change UHP 2026-09-12, do not establish a new HarnessRouter Claude adapter feature, and do not prove native Claude Code adoption of UHP.
2.1.269: plugin evaluation, workflow fan-out and resumed-headless fidelity
Section titled “2.1.269: plugin evaluation, workflow fan-out and resumed-headless fidelity”Claude Code 2.1.269 adds a first-party claude plugin eval surface that runs a plugin evaluation suite and emits scored reproducible JSON and HTML reports. It also adds CLAUDE_CODE_WORKFLOW_MAX_CONCURRENT_AGENTS with an allowed range of 1–256, giving operators an explicit per-run ceiling for inference-bound Workflow fan-outs rather than relying only on the previous fixed behavior.
Several fixes matter directly to embedded/headless operation: resumed headless sessions no longer lose a turn’s replies when the model changes or a request is retried mid-turn; remote and headless sessions no longer report “waiting for your input” while background agents are still running; synchronized plugin MCP servers reconnect when a remote session resumes; and permission_denials in --output-format stream-json now includes Read, Edit and Write calls blocked by path-scoped deny rules. Organization plugins enabled through managed settings also load in headless sessions, and an alwaysLoad MCP server that finishes connecting mid-conversation can be used on the next turn without an extra tool-search round trip in first-party sessions with telemetry disabled.
The release also tightens execution and local-plugin boundaries. A deny/ask permission rule beginning with ! now applies only within the settings source that wrote it, with a bare ! ignored; Edit() deny rules and the write-path check now apply to the file written by Bash tee; plugin archives extracted for a session no longer remain readable by other local users, preserve world-writable bits or leave stale files behind on re-extraction; and plugin LSP servers receive exit even when they reject shutdown, reducing session-end process leakage.
These are Claude Code host/runtime, policy and MCP-integration semantics. They do not change UHP, ACP or MCP wire protocols, do not establish a Claude-specific HarnessRouter adapter revision, and do not establish native UHP adoption by Claude Code.
2.1.270: long-session permission regression fix
Section titled “2.1.270: long-session permission regression fix”Claude Code 2.1.270 is a narrow corrective release for a regression introduced in 2.1.269: read-only Git commands run through Bash could unexpectedly begin asking for permission after a session had been running for a while. Anthropic’s published changelog identifies this as the sole 2.1.270 change. For embedded or unattended harness hosts, the significance is behavioral stability of an already-read-only operation rather than a new permission model or protocol surface.
This correction does not change UHP, ACP or MCP wire semantics, does not add a HarnessRouter Claude adapter capability, and does not establish native UHP adoption by Claude Code.
2.1.277: AGENTS.md becomes a first-party project-instruction surface
Section titled “2.1.277: AGENTS.md becomes a first-party project-instruction surface”Claude Code 2.1.277 adds released AGENTS.md support through the built-in agents-md mod. The default claude-md-or-agents-md mode keeps existing Claude-native behavior when a project has its own CLAUDE.md; otherwise Claude Code loads AGENTS.md and .claude/AGENTS.md files from the filesystem-root-to-working-directory ancestry as project instruction files. Nested AGENTS.md files can be attached when Read crosses into their directory, subject to same-directory CLAUDE.md precedence and duplicate suppression.
The /config Project instructions control also exposes claude-md (Claude files only), claude-md-and-agents-md (load both families) and managed-only (drop project/user/local instruction files while keeping organization-managed instructions and memory). Plugin options come from user, command-line or managed settings rather than project .claude/settings.json; the old projectInstructions key is still mapped for compatibility. Forked Agent-tool children inherit already-delivered nested instruction files so the same instructions are not attached twice. Anthropic’s release note says the new AGENTS.md support is not yet available on Bedrock, Vertex or Foundry.
This is meaningful harness interoperability because repositories can now present an AGENTS.md instruction surface to Claude Code without renaming it to CLAUDE.md. It is still host-side prompt/instruction loading, not a UHP, MCP, ACP or A2A wire change, not evidence that AGENTS.md is a UHP standard, and not native UHP adoption by Anthropic. HarnessRouter’s Claude install remains unpinned on fresh self-host volumes, so an operator may receive this upstream behavior independently of any Claude-specific HarnessRouter adapter revision.
The same release also fixes claude -p and Agent SDK sessions that could hang without a result after an internal error; they now report the error and exit with code 1. That improves headless finality but likewise remains upstream Claude runtime behavior.
Post-release current main: attachment-disabled runs suppress nested AGENTS.md
Section titled “Post-release current main: attachment-disabled runs suppress nested AGENTS.md”PR #95417, merged 18 September 2026 at 19:27:54 UTC as 2fc72b2918b43710ff4c7c73be173100c2cbe379, corrects a narrow boundary in the new built-in agents-md behavior. A Read no longer attaches nested AGENTS.md context when Claude Code’s engine is running in a mode where it attaches nothing to the turn, specifically a --bare run through CLAUDE_CODE_SIMPLE or a run with CLAUDE_CODE_DISABLE_ATTACHMENTS enabled.
The mod reads those two environment switches on every Read, using the same truthy spellings as the engine (1, true, yes, on, case-insensitive and whitespace-trimmed). This means a settings env block or managed delivery that changes either switch during a session is followed by subsequent reads rather than being frozen at startup. The broader instruction-file walk remains aligned with the engine: where modes such as --bare without --add-dir, --safe-mode, or CLAUDE_CODE_DISABLE_CLAUDE_MDS cause the engine to load no instruction files, the mod’s ancestor walk finds none to add.
The architectural invariant is repository-instruction interoperability must not bypass the host’s own context-suppression mode. Supporting a shared instruction filename does not grant that filename an independent authority to re-enter a turn after the host has disabled instruction/context attachments. This fix is merged current-main behavior after v2.1.277; it is not evidence of a new Claude Code stable release and it does not change UHP, MCP, ACP or A2A wire semantics.
Built-in hook-module mods in the stable tag ancestry
Section titled “Built-in hook-module mods in the stable tag ancestry”PR #93215 and follow-up PR #93244 introduced the earlier built-in mod source, and PR #95409 adds agents-md. Anthropic now publishes source for four built-in mods: sec-default, diff, telemetry and agents-md. The first three remain the previously documented hook-module architecture; agents-md is now surfaced as released user-facing project-instruction behavior in v2.1.277. Function-hook APIs around the mod system may still evolve independently of the stable AGENTS.md user-facing feature.
Permission-boundary hardening through 2.1.277
Section titled “Permission-boundary hardening through 2.1.277”The current release retains the permission-hardening line. Path rules containing parentheses are no longer dropped in a way that can leave intended read-only folders writable; invalid deny-pattern handling fails toward the literal guarded path instead of making every edit fail; Bash permission checks no longer auto-approve zsh assignments that conceal command substitution in REPORTTIME, REPORTMEMORY or DIRSTACKSIZE; and Glob/Grep no longer probes a search path on disk before the permission decision.
2.1.260 also reverts an over-broad 2.1.259 change that applied Read() deny rules to Bash arguments and caused false denials such as npm run build under a Read(./**/build/**) rule. 2.1.261 further expands the dangerous-rm safety prompt to catch rm -rf operating on positional parameters or inside double-quoted sh -c scripts, and auto mode treats URLs that embed content in public diagram-renderer services as uploads that are not auto-approved unless requested. 2.1.265 adds the plugin-path containment and nested-repository clean-filter fixes described above; 2.1.267 adds the fetched-marketplace backslash-containment fix and fail-closed managed allowlists; 2.1.268 extends path-rule enforcement across symlink aliases and unanalyzable same-line shell constructs while removing secrets from plugin/MCP error surfaces. 2.1.269 further scopes leading-! deny/ask rules to their originating settings source, applies Edit()/write-path enforcement to Bash tee destinations, and hardens extracted plugin file permissions and replacement hygiene. 2.1.270 restores expected read-only Git behavior after the permission-prompt regression introduced in 2.1.269.
These are Claude Code security/runtime fixes, not UHP security requirements or evidence of UHP conformance.
What is not proven
Section titled “What is not proven”Why the distinction matters
Section titled “Why the distinction matters”A reference implementation can adapt an existing harness without that harness vendor changing its own API. Native adoption would be a stronger ecosystem signal: it would mean a vendor, tool or independent runtime exposes or consumes UHP directly, reducing dependence on one adapter implementation.
Likewise, internal multi-session or subagent coordination does not change the outer protocol boundary. A single UHP-visible task may be implemented by a harness that coordinates multiple internal sessions or children; UHP conformance evaluates the server-visible contract rather than standardizing that internal graph.
Current developer implication
Section titled “Current developer implication”If you are evaluating UHP today, test the behavior you need through the official conformance suite and your target backend. Do not assume that every backend feature maps perfectly just because the common API exists. The protocol deliberately defines common semantics, while backend-specific capabilities may continue to differ.
For Claude Code specifically, distinguish three layers: the normative UHP contract, HarnessRouter’s released adapter/plugin behavior, and Claude Code’s own rapidly evolving session/composition controls. As of this cutoff, v2.1.277 / tag ca02e7de is the current upstream stable coordinate; checked main is 6ce37e9f, with PR #95417 / 2fc72b29 providing the material post-release AGENTS.md attachment-boundary correction and the following 6ce37e9f commit unrelated to that feature. HarnessRouter stable and checked main are v0.18.4 / efd320b3, and no reviewed primary source turns the upstream runtime or AGENTS.md changes above into UHP semantics.
Related pages
Section titled “Related pages”Read Harness composition and subagent delegation, UHP architecture, conformance, HarnessRouter, and the adoption tracker.
Primary sources
Section titled “Primary sources”- Claude Code
v2.1.277 - Claude Code
v2.1.277changelog - Claude Code PR #95409 — built-in AGENTS.md project-instructions mod
- Claude Code PR #95409 merge
a92ea1cd - Claude Code
v2.1.277tag commitca02e7de - Claude Code PR #95417 — suppress nested AGENTS.md when turn attachments are disabled
- Claude Code PR #95417 merge
2fc72b29 - Claude Code checked
main6ce37e9f - Claude Code
v2.1.270 - Claude Code
v2.1.269 - Claude Code
v2.1.268 - Claude Code PR #93215 — built-in hook-module mods
- Claude Code PR #93244 — mod API/telemetry fixes and diff backend seam
- Claude Code
v2.1.267 - Claude Code
v2.1.266 - Claude Code
v2.1.265 - Claude Code
v2.1.261 - Claude Code
v2.1.260 - Claude Code
v2.1.251 - Claude Code
v2.1.248— cross-session messaging and restricted mode - HarnessRouter
v0.18.4 - HarnessRouter checked
mainefd320b3 - HarnessRouter
v0.15.7— explicit Claude/OpenCode lost-resume reporting - HarnessRouter
v0.9.0— Claude Code plugins and stdio MCP - HarnessRouter Claude plugin-dir merge —
95b96d7 - HarnessRouter Community Edition repository
- UHP
2026-09-12architecture specification