Two spot-check fixes (T-178, T-179), both grounded in a boundary test of
the stream-json wire (findings folded into the spike doc):
- Harness-injected user messages (skill loads, slash-command expansions,
system reminders) carry isSynthetic on the wire (isMeta in the
transcript). They were rendering as blue "you" cards though the user
never typed them; now UserMessage.injected flags them and the view
shows a muted, collapsed "context" card instead.
- Permission prompts now show the command/input being permitted (a
capped, scrollable code block) so you can see what you approve. Instead
of fully hiding a prompted tool-use, once resolved it collapses to a
one-line summary with a green (approved) or red (denied) border; the
session tracks per-tool_use_id outcome and the view colours it. The
result is kept.
Corrects an earlier wrong assumption: the Skill tool is auto-allowed
(no permission prompt); the inject only appears once the Skill tool is
actually invoked, which is why deny-captures missed it.
T-178, T-179, D-78.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>