Skip to content

Releases: M-Pineapple/warp-command-runner

v8.0.0 — remote MCP for phone and cloud hosts

Choose a tag to compare

@M-Pineapple M-Pineapple released this 27 Aug 08:41
43944d7

Stdio is unchanged. Opt-in Streamable HTTP so Grok, ChatGPT, and Claude can call this Mac when you publish HTTPS yourself.

Added

  • warp-command-runner --http — Streamable HTTP on 127.0.0.1 only (default port 8741)
  • OAuth 2.1 with PKCE, Dynamic Client Registration, protected-resource metadata, refresh tokens
  • remote block in config.json: listenPort, publicBaseURL, allowKeystrokeTools (requireMacApproval is parsed and reserved; it does not yet show a Mac prompt)
  • --remote-doctor, --install-agent, --uninstall-agent
  • docs/REMOTE.md and config/remote.example.json (fictional https://mcp.example.com)

Changed

  • Remote sessions refuse the five Warp-routing tools unless allowKeystrokeTools is true. Use execute_pipeline.
  • Compatibility docs describe the tunnel path. This project still does not host a relay.

Notes

  • The public URL is whatever you create (Cloudflare named tunnel, Tailscale Funnel, or a reverse proxy on your account). Quick tunnels change hostname every start.
  • The Mac must stay awake and the --http process must stay running.
  • ChatGPT write tools need Developer mode. Whether iOS can invoke them is a host limit.

Upgrading: rebuild with ./build.sh, then rm -rf "/Applications/Warp Command Runner.app" && cp -R .build/release/warp-command-runner.app "/Applications/Warp Command Runner.app" and restart the MCP host. For remote MCP, run warp-command-runner --http (or --install-agent) and point your own tunnel at 127.0.0.1:8741. See docs/REMOTE.md.

See CHANGELOG.md for the full list.

v7.0.0 — Warp Command Runner rebrand

Choose a tag to compare

@M-Pineapple M-Pineapple released this 27 Aug 06:38

Formerly Claude Command Runner. Same MCP server; names and docs match how the protocol actually works.

The v6 binary already spoke standard MCP over stdio. Any local host (Warp Agent with Grok/GPT/Claude/Gemini, Claude Desktop, ChatGPT desktop, Cursor, VS Code, Continue, …) could call it. The product name still said "Claude", which hid that. v7.0 renames the project and records the compatibility boundary: local MCP hosts yes, browser cloud chats no.

Changed

  • Package, executable, Swift module, .app bundle, and MCP serverInfo name: warp-command-runner / Warp Command Runner
  • Bundle ID com.m-pineapple.warp-command-runner (v6 TCC grants on the old ID do not transfer — re-grant once)
  • Config/history directory ~/.warp-command-runner (copies ~/.claude-command-runner on first launch; old folder is not deleted)
  • Capture files /tmp/wcr_* (still reads leftover /tmp/claude_* from in-flight v6 commands)
  • Shell shim socket /tmp/wcr-shell-shim-<uid>.sock; installer replaces the v6 rc marker
  • WCR_CODESIGN_IDENTITY (the v6 CCR_CODESIGN_IDENTITY alias still works)
  • Docs and config/ snippets for Warp, Claude Desktop, ChatGPT desktop, Cursor, VS Code, and generic stdio
  • New docs/COMPATIBILITY.md

Docs

  • Cursor splits MCP command on spaces, so /Applications/Warp Command Runner.app/... fails with spawn /Applications/Warp ENOENT. Run helper/install-cursor-wrapper.sh and point Cursor at ~/.local/bin/warp-command-runner. Warp and Claude Desktop keep the official bundle path. Do not rename the .app.

Migration

  1. Build v7, copy the bundle to /Applications/Warp Command Runner.app
  2. Change every MCP config key and path from claude-command-runner to warp-command-runner
  3. Re-grant Full Disk Access, Input Monitoring, Accessibility, and Automation for the new bundle
  4. Restart the host. Config and command history should already be in ~/.warp-command-runner

Notes

  • This is not a remote/HTTPS MCP. Do not tunnel it to chatgpt.com / grok.com / claude.ai.
  • Tool count and behaviour are unchanged from 6.2.0.

Upgrading: rebuild with ./build.sh, then rm -rf "/Applications/Warp Command Runner.app" && cp -R .build/release/warp-command-runner.app "/Applications/Warp Command Runner.app" and restart the MCP host.

See CHANGELOG.md for the full list.

v6.2.0 — full code audit: reliability, security ordering, real test suite

Choose a tag to compare

@M-Pineapple M-Pineapple released this 09 Jun 18:26

A full audit of the codebase (~9,500 lines) drove this release: two classes of live bug fixed, a security guard that only existed in dead code wired into the live path, ~900 lines of dead code removed, and the placeholder test replaced with a 30-test suite.

Fixed

  • MCP protocol corruption — DatabaseManager logged to stdout (the JSON-RPC channel), including on every execute_command. All logging now goes to stderr.
  • Pipe deadlocks — every spawn site waited for exit before reading pipes; children writing > ~64 KB deadlocked permanently. New shared runProcess() drains pipes concurrently.
  • Unbounded hangs — execution timeouts added everywhere (pipeline/SSH 600s, file-watch 300s, AppleScript 30s) with SIGTERM → SIGKILL escalation; blocking waits moved off the Swift cooperative pool.
  • Interactive-command guard now runs on the live execute path — vim, bare ssh, top etc. are blocked with a helpful message instead of hanging the capture script. Pipe-spanning patterns (curl … | sh) can now match.
  • Security ordering — blocked commands were saved to history before the block check (recorded as executed). Checks now run first and cover the full command including the cd prefix; working_directory is escaped against quote-breakout.
  • Database hardening — serial queue + SQLITE_OPEN_FULLMUTEX, NULL-handle guards, PRAGMA user_version schema versioning, and retention cleanup that actually runs at startup (commands + analytics; the cleanup paths previously had no callers).
  • FileWatcher — suspended-source cancel crash, unbalanced suspend/resume, and actor-blocking command execution all fixed.
  • Schema/handler mismatches — open_terminal_tab honours working_directory; numeric parameters accept JSON numbers as declared.

Removed

  • The vestigial --port / -p option (the TCP listener it configured was retired in v6.0). Remove it from your MCP config args if present.

Tests

  • 30-test suite: detector table tests, DB round-trips + 50-writer concurrency, large-output no-deadlock proof, timeout termination, live injection-prevention check, output-capture script executed for real.

Upgrading: rebuild with ./build.sh, then rm -rf "/Applications/Claude Command Runner.app" && cp -R .build/release/claude-command-runner.app "/Applications/Claude Command Runner.app" and restart Claude Desktop. TCC grants persist if you sign with the same identity.

See CHANGELOG.md for the full list.

v6.1.0 — template CRUD, real shell env capture, shim exit-code confirmation

Choose a tag to compare

@M-Pineapple M-Pineapple released this 09 Jun 18:26

Added

  • delete_template — completes the template CRUD (save / run / list / delete). Tool count 39 → 40.
  • Shell-shim exit-code confirmation — when the optional shim is active, get_command_output uses the shell's authoritative exit code and can confirm completion even if the /tmp capture is missing. Safe no-op without the shim.

Changed

  • capture_environment captures your real shell environment — spawns your login + interactive shell so ~/.zprofile / ~/.zshrc are sourced, with a timeout watchdog and graceful fallback.
  • execute_pipeline steps are recorded in command history (exit code + duration).
  • suggest_command accepts working_directory so contextual git / Swift / Node suggestions actually fire; no more junk globs for natural-language queries.
  • TerminalConfig.getPreferredTerminal() honours config.json before auto-detecting.

See CHANGELOG.md for details.

v6.0.5 - correctness fixes

Choose a tag to compare

@M-Pineapple M-Pineapple released this 07 Jun 14:00

Correctness fixes from auditing each tool against its documented behavior.

  • open_terminal_tab (Warp): reports tab creation as dispatched/unconfirmed; the returned id is a local tracking id, not a Warp session UUID
  • get_command_output: the documented "last" alias resolves to the most recent output
  • add_file_watch: the pattern filter is now applied
  • command history: completed commands record exit code and duration instead of staying pending
  • self_check: Warp running-state detection fixed (matches the app path)
  • internal: resolved a latent DispatchQueue deadlock in DatabaseManager.updateCommand

See CHANGELOG.md for full details.

v6.0.4 — documented full macOS Sequoia TCC setup recipe

Choose a tag to compare

@M-Pineapple M-Pineapple released this 16 May 11:13

[6.0.4] - 2026-05-16 — full macOS Sequoia TCC setup recipe documented

Why this release exists

v6.0.3 shipped the .app bundle wrapper. Verifying it end-to-end on a live install revealed a fifth layer of macOS Sequoia's TCC enforcement that wasn't obvious from the code: kTCCServiceSystemPolicyAllFiles (Full Disk Access) is checked by the sandbox preflight before the AppleEvents/Input Monitoring chain even runs. Bundle ID grants in System Settings → Privacy & Security → Automation/Input Monitoring don't help if the bundle lacks Full Disk Access — sandboxd denies first, the user sees the misleading "send keystrokes" error, and they spend hours toggling the wrong panels.

Once FDA is granted to the bundle (in addition to Automation, Input Monitoring, and Accessibility), the chain works permanently. Empirically verified on macOS Sequoia 26.x with a 6-hour debugging session captured in detail.

Documentation

  • README "🛡️ macOS Sequoia full setup recipe (the 7 ordered steps)" — a new top-level section under Installation replacing the old "Stable code signing" section. Documents the empirically-verified procedure for getting the 5 keystroke-routing tools working on macOS Sequoia:
    1. Have an Apple Development cert (or self-signed Code Signing cert) in Keychain
    2. ./build.sh produces the .app bundle at .build/release/claude-command-runner.app/
    3. Copy the bundle into /Applications/ (TCC refuses to prompt for bundles in dev directories — this was the second-to-last layer)
    4. Point Claude Desktop / Warp Agent config at the /Applications/ bundle path
    5. tccutil reset AppleEvents/ListenEvent/PostEvent/Accessibility for the bundle ID
    6. Grant THREE permissions in System Settings → Privacy & Security: Full Disk Access (the surprise), Input Monitoring, Accessibility
    7. Restart Claude Desktop, accept the Automation prompt on first execute_command
  • Includes the diagnostic command for reading the TCC log (log show --predicate 'process == "tccd"') and what to look for in the output (promptPolicy=0 vs =2, Service Policy: Denied, attribution chain identifier).
  • README "Error 1002" troubleshooting rewritten to point users at the canonical recipe instead of repeating outdated partial fixes. Adds a quick-triage matrix mapping log signals to specific recipe steps.
  • MCP serverInfo.version 6.0.3 → 6.0.4.

Notes

  • No code changes — pure documentation pass that captures real install experience.
  • Tool count unchanged at 39.
  • The bundle architecture from v6.0.3 stays exactly as-is; this release is about helping the next user avoid the trap.

v6.0.3 — .app bundle wrapper (TCC prompts finally appear)

Choose a tag to compare

@M-Pineapple M-Pineapple released this 16 May 10:59

[6.0.3] - 2026-05-16 — .app bundle wrapper (TCC prompts actually appear now)

Why this release exists

v6.0.2 added stable code-signing to fix cdhash drift across rebuilds. That solved one layer of the TCC problem but uncovered the next: modern macOS (Sequoia and later) silently denies TCC permission prompts for CLI binaries that lack an embedded Info.plist with NSXxxUsageDescription strings. No dialog appears; no error in System Settings; just silent denial. The 5 keystroke-routing tools (execute_command, execute_with_auto_retrieve, execute_with_streaming, run_template, send_to_session) hit this. Hours of TCC-cleanup and re-grant cycles did not resolve it — the permission prompts the user needed to grant were never being shown because the binary had no Info.plist to drive them.

Empirical confirmation from the live TCC log: auth_value=1 (Unknown) on every request from claude-command-runner to kTCCServiceListenEvent, no Prompting entry ever appearing — the textbook silent-deny pattern for CLI binaries.

Fixed

  • scripts/make-app-bundle.sh (new) wraps the built CLI binary in a proper .app bundle at .build/release/claude-command-runner.app/. The bundle structure is minimal — Contents/MacOS/claude-command-runner + Contents/Info.plist, no Resources, no icon. The Info.plist declares:
    • CFBundleIdentifier=com.m-pineapple.claude-command-runner (stable, reverse-DNS, so TCC can target the bundle by identity rather than by cdhash)
    • LSUIElement=true (don't show in Dock when launched — we're a CLI, not a UI app)
    • NSAppleEventsUsageDescription, NSInputMonitoringUsageDescription, NSAccessibilityUsageDescription — these are what macOS shows in the permission prompt; missing them = silent denial
  • build.sh now invokes scripts/make-app-bundle.sh after the binary is built (and code-signed if CCR_CODESIGN_IDENTITY is set). The bundle is signed as a unit when the env var is present.
  • config/claude-desktop-config.json and config/warp-agent-mcp.json updated to point at the binary inside the bundle: .build/release/claude-command-runner.app/Contents/MacOS/claude-command-runner. README + docs/WARP_AGENT.md follow.
  • MCP serverInfo.version 6.0.2 → 6.0.3.

Changed (potentially breaking — see Migration)

  • Recommended install path moved from .build/release/claude-command-runner to .build/release/claude-command-runner.app/Contents/MacOS/claude-command-runner. The bare-binary path still exists (we keep a copy for backwards compat) and still works for the 34 tools that don't use keystroke routing. The 5 keystroke-routing tools require the bundle path.

Migration (existing v6.0.x users)

Edit your config files and append .app/Contents/MacOS/claude-command-runner to the existing path:

-  "command": ".../claude-command-runner/.build/release/claude-command-runner",
+  "command": ".../claude-command-runner/.build/release/claude-command-runner.app/Contents/MacOS/claude-command-runner",

Restart Claude Desktop / Warp. On the next execute_command, macOS should finally prompt for AppleEvents / Input Monitoring permission — grant once and it sticks (combined with v6.0.2's stable signing, the grant survives future rebuilds).

If you'd previously added the bare claude-command-runner binary to System Settings → Privacy & Security → Input Monitoring / Automation, those entries become orphans (different identity from the bundle). Safe to remove for hygiene; not required for functionality.

Notes

  • Tool count unchanged: 39.
  • No source code changes beyond the version-string bump.
  • scripts/make-app-bundle.sh is idempotent — re-runs overwrite the bundle cleanly.

v6.0.2 — optional stable code signing (eliminates TCC drift across rebuilds)

Choose a tag to compare

@M-Pineapple M-Pineapple released this 16 May 06:58

[6.0.2] - 2026-05-16 — stable code signing opt-in

Why this release exists

Live diagnosis on a user's machine revealed that the persistent "osascript is not allowed to send keystrokes (1002)" issue affecting the 5 AppleScript-routed tools is not a configuration problem — it's a structural one. Empirical evidence captured via log show --predicate 'process == "tccd"':

  1. The TCC service being denied is kTCCServiceAppleEvents, NOT kTCCServiceAccessibility. The error message's "keystrokes" wording is misleading; the actual gate failing is the AppleEvents/Automation permission.
  2. The binary is ad-hoc signed (Swift's default for swift build). Every rebuild produces a new cdhash. macOS treats each rebuild as a separate program for TCC purposes, orphaning the previous grant.
  3. The user's System Settings → Privacy & Security → Automation panel had three separate claude-command-runner entries — one per rebuild cycle — visually confirming the drift.
  4. Claude Desktop spawns the MCP server via Apple's responsibility_spawnattrs_setdisclaim helper (/Applications/Claude.app/Contents/Helpers/disclaimer), which deliberately prevents Claude.app's TCC grants from propagating to the child. So granting Claude.app permissions doesn't help; the child binary's own identity is what TCC checks.

Every user who ever rebuilds this project hits this. The first install works (TCC prompts, user grants). The first git pull && ./build.sh silently breaks it. Until v6.0.2, the only "fix" was to re-grant after every rebuild — tedious and confusing.

Fixed

  • build.sh now supports stable code signing via CCR_CODESIGN_IDENTITY env var. When set, the binary is signed with the user's chosen certificate (typically a self-signed cert from Keychain Access). Resulting cdhash is stable across rebuilds. Grant TCC once, it persists indefinitely. Opt-in to preserve backwards compatibility — unset means ad-hoc behavior unchanged from v6.0.x.
  • build.sh: dropped stale --port 9876 invocation hint from the post-build install instructions (the TCP listener was deleted in Tier A of v6.0.0).
  • build.sh: updated install hint to point at both Claude Desktop and Warp Agent config paths (was Warp-only and outdated).
  • MCP serverInfo.version 6.0.1 → 6.0.2.

Documentation

  • README "Stable code signing" section added under Installation (after the optional shell shim step). Explains the cdhash-drift problem in 3 sentences, the 5-step Keychain Access cert-generation flow, the CCR_CODESIGN_IDENTITY env var, verification command, and the execute_pipeline fallback for users who'd rather not sign.
  • CHANGELOG v6.0.2 entry (this one) captures the empirical TCC log evidence so future readers don't have to re-do the investigation.

Migration

For existing users hitting the TCC stuckness:

  1. Generate a self-signed code-signing cert in Keychain Access (5 steps, see README)
  2. export CCR_CODESIGN_IDENTITY="claude-command-runner" (or whatever you named the cert)
  3. ./build.sh
  4. Remove all stale claude-command-runner entries from System Settings → Privacy & Security → Automation
  5. Restart Claude Desktop
  6. Trigger an execute_command → TCC prompts fresh → grant → done. Permanent until you replace the cert.

Notes

  • No behavior change for users who don't set CCR_CODESIGN_IDENTITY — backwards-compatible.
  • Tool count unchanged: 39.
  • No API changes.

v6.0.1 — parser fix, decoder robustness, troubleshooting docs

Choose a tag to compare

@M-Pineapple M-Pineapple released this 07 May 17:01

[6.0.1] - 2026-05-07 — patch follow-up to v6.0.0

Three real findings surfaced from the v6.0.0 live verification, plus one already-staged fix that was waiting for a tag.

Fixed

  • execute_and_parse git_status parser garbled output for human-readable input. The parser was hardcoded for git status --porcelain (2-char status code at line start) and would treat the first character of every prose line as a status code — producing nonsense like Staged: 3 file(s) • O branch main for actual git status output. v6.0.1 now detects format (presence of "On branch", "HEAD detached", "Changes to be committed", etc.) and dispatches to a human-format parser or the existing porcelain parser. Output for both formats is now correct.
  • Configuration decoder failed loudly with keyNotFound errors when an existing on-disk ~/.claude-command-runner/config.json predated one or more top-level schema fields (e.g. security). Swift's auto-synthesized Codable init uses decode (not decodeIfPresent) and ignores property defaults. v6.0.1 adds a custom init(from:) to Configuration that uses decodeIfPresent ?? <default> for every top-level field. Old configs continue to load without error logs; new fields silently fall back to defaults.
  • MCP serverInfo.version was hardcoded to "5.0.0". v6.0.1 reports "6.0.1". (Already fixed on main between v6.0.0 and v6.0.1; rolled into this tag.)

Documentation

  • README troubleshooting for "Error 1002 / osascript not allowed to send keystrokes" rewritten with a "Why this is so painful" section explaining macOS responsible-process attribution. Step 5 (manual osascript -e 'tell application "System Events" to keystroke "x"' from a real shell) is now flagged as mandatory, not optional — that's the step that actually causes macOS to re-prompt and unstick the chain. Empirically validated during v6.0.0 install: every System Settings toggle was correct, full Mac restart performed, but the chain only unstuck after step 5. Also adds a workaround note: execute_pipeline is a fully-functional substitute for execute_command while TCC is being figured out — no Apple Events involved.

Notes

  • Tool count unchanged: still 39.
  • No API breaking changes.
  • AGPL hygiene unchanged (no new vendoring).

v6.0.0 — Warp re-pivot (dual-consumer MCP, deeplinks, OSC 777, shell shim)

Choose a tag to compare

@M-Pineapple M-Pineapple released this 07 May 14:21

[6.0.0] - 2026-05-07 — Warp re-pivot

This release is a re-pivot back to Warp Terminal, triggered by Warp going open source under AGPL-3.0 (github.com/warpdotdev/warp) in early May 2026. It re-establishes Warp as the primary integration target, replaces fragile AppleScript paths with documented surfaces, and adds a new install path: Warp's native agent panel as a first-class consumer alongside Claude Desktop.

Headline

claude-command-runner is now a dual-consumer MCP server: the same binary serves both Claude Desktop and Warp's built-in agent. Same code, same tools, just two consumers. See docs/WARP_AGENT.md for the new install path.

Added

  • Warp Agent registration story (Tier D). Documented ~/.warp/.mcp.json setup so Warp's native agent panel can call our tools. Sample at config/warp-agent-mcp.json.
  • focus_warp_session tool — dispatches warp://session/<uuid> to focus a previously-opened pane. Requires a UUID Warp itself recognises (typically from the optional shell shim's OSC 777 stream).
  • emit_warp_event tool — builds a printf invocation that emits an OSC 777 warp://cli-agent JSON event into Warp's notification UI. Schema reimplemented from upstream event/v1.rs. Surfaces session_start / prompt_submit / tool_complete / stop / permission_request / idle_prompt.
  • shell_shim_status tool — reports the optional shell shim's listening state and recent events.
  • Optional shell shim (Tier E, opt-in beta, helper/install-shim.sh). Adds zsh/bash hooks that emit preexec/command_finished events to a per-uid Unix domain socket the MCP listens on. Auto-disables outside Warp panes (gated on $WARP_SESSION_ID). Observability surface in v6.0; execute_command auto-routing through shim events is deferred to v6.0.x.
  • Workspace profiles → Warp launch configs (Tier C). save_workspace_profile accepts include_warp_launch_config: true; when set, also writes a YAML to ~/.warp/launch_configurations/<name>.yaml so the profile appears in Warp's launch UI. Schema reimplemented from upstream LaunchConfig / TabTemplate / PaneTemplateType / CommandTemplate. Env vars are not emitted into the YAML (Warp's schema does not have a top-level env map); they remain in the private CCR JSON.
  • Session UUID tracking — TerminalSession now carries a locally-minted UUID (returned by open_terminal_tab). Used by our registry; not bound to Warp's internal session UUID.
  • PRODUCT.md and TECH.md — checked-in product/tech specs for v6.0.

Changed

  • open_terminal_tab (Warp path) uses warp://action/new_tab?path=... instead of clicking menu item "New Tab" via System Events. The open path no longer requires Accessibility permission. Directory is baked into the URL — no follow-up cd keystroke. AppleScript path remains for iTerm2 / Terminal / Alacritty (unchanged).
  • README.md — rewritten for the dual-consumer story. Tool count corrected from 30 to 39 (was previously under-counted; v6.0 adds 3 new).
  • swift-sdk pinned to 0.10.x with a reproducible patch script (scripts/patch-swift-sdk.sh). Previous loose from: "0.1.0" resolved 0.9.0 and failed under current Swift toolchains. The patch applies nonisolated(unsafe) to two Bool decls in NetworkTransport.swift. Build is reproducible from a fresh clone via ./build.sh.
  • config/ — dropped --port 9876 and --verbose from the example claude_desktop_config.json (port 9876 was for the now-deleted TCP listener). Removed warp-mcp-config.json and warp-mcp-config-correct.json; replaced with a single canonical warp-agent-mcp.json.

Removed (dead code)

  • WarpDatabaseIntegration.swift (260 LOC) — never reached from any registered tool. Hardcoded Warp SQLite schema; would silently break on Warp updates.
  • CommandReceiverService.swift (201 LOC) — TCP listener on 127.0.0.1:9876 with mock-only handlers; never invoked from production. The live MCPService struct that was sharing the file has been extracted to its own file.
  • CommandHistoryManager.loadFromWarpDatabase and the warpDB property — neither was reachable.
  • The unreachable Task-based background monitor in CommandHandlers.swift — dispatch goes through CommandHandlersStable. The dead Task was the prior crash trigger.

Fixed

  • README claimed 30 tools; the dispatch table actually registered 36. Six previously-undocumented tools surfaced: set_notification_preference, cleanup_sessions, list_file_watches, delete_workspace_profile, list_ssh_profiles, delete_ssh_profile. With v6.0's three new tools (focus_warp_session, emit_warp_event, shell_shim_status), the live count is 39.

Tool count

Version Tools Note
v5.0.0 advertised 30 README claim
v5.0.0 actual 36 dispatch table
v6.0.0 39 dispatch table

Migration

  • Existing Claude Desktop users: edit claude_desktop_config.json to drop --port 9876 from args. The MCP server still tolerates the flag (it's parsed and ignored), but it serves no purpose post-v6.0.
  • New Warp Agent users: see docs/WARP_AGENT.md.
  • Optional shim users: helper/install-shim.sh adds a clearly-marked block to your ~/.zshrc or ~/.bashrc. helper/uninstall-shim.sh removes it.
  • Build: run ./build.sh (now invokes scripts/patch-swift-sdk.sh automatically). Or for manual builds: swift package resolve && ./scripts/patch-swift-sdk.sh && swift build -c release.

Non-goals (deliberately out of scope)

  • Bridging Claude Desktop conversations into Warp (would require server-push; reinvents Claude Code).
  • Replacing Claude Code as a TUI agent in a Warp pane.
  • Reading Warp's internal SQLite (~80 Diesel migrations in 5 years; schema unstable).
  • Becoming a Warp plugin (no third-party plugin API exists; CLIAgent registry is a closed enum).
  • Wave Terminal support (the prior local repurposing was incorrect; Wave is not a target).

AGPL hygiene

Warp is AGPL-3.0. Our MCP communicates with Warp over IPC (warp:// URLs and OSC escape sequences) and through the MCP protocol — copyleft does not propagate. No Warp source is vendored. All schemas (OSC 777 event JSON, launch config YAML) are reimplemented from observed shape, not copied.