Problem
cao launch --env is session-wide and the forwarded-env blocklist intentionally drops CLAUDE* keys (#248), so there is no way to point ONE claude_code worker at an alternate config/auth directory (CLAUDE_CONFIG_DIR) while other Claude agents in the same session keep the default. Multi-account setups (a second Claude identity as a worker) are impossible today; the ${VAR} interpolation from #155 happens at install time over the profile text, not in the process env.
Proposal
An optional env: mapping in the agent profile, merged into that agent's terminal environment at launch on a separate trusted channel: profiles are installed configuration (they can already launch arbitrary executables via mcpServers.command), so the inherited-env prefix blocklist adds no trust boundary there; keep the per-value byte cap (argv limit) and CAO identity vars still win last. Scoped to the declaring agent's terminal only — never persisted to the session env.
Implementation ready in a fork (model field + TmuxClient/herdr trusted merge + terminal_service plumbing, with tests); PR follows.
Problem
cao launch --envis session-wide and the forwarded-env blocklist intentionally dropsCLAUDE*keys (#248), so there is no way to point ONEclaude_codeworker at an alternate config/auth directory (CLAUDE_CONFIG_DIR) while other Claude agents in the same session keep the default. Multi-account setups (a second Claude identity as a worker) are impossible today; the ${VAR} interpolation from #155 happens at install time over the profile text, not in the process env.Proposal
An optional
env:mapping in the agent profile, merged into that agent's terminal environment at launch on a separate trusted channel: profiles are installed configuration (they can already launch arbitrary executables viamcpServers.command), so the inherited-env prefix blocklist adds no trust boundary there; keep the per-value byte cap (argv limit) and CAO identity vars still win last. Scoped to the declaring agent's terminal only — never persisted to the session env.Implementation ready in a fork (model field + TmuxClient/herdr trusted merge + terminal_service plumbing, with tests); PR follows.