article feature

Persistent IPython: the single model-facing tool

Prime Agent exposes one built-in model tool: a persistent IPython kernel that keeps variables, imports, and functions across ordinary calls and compaction. File edits, shell commands, skills, and subagent calls are invoked through Python code. The kernel runs with your OS permissions and is not a security sandbox.

v v0.7.1reviewed 2026-08-09evidence code-derivedsources S008, S007, S012, S013cutoff 2026-08-09
Features

Pinned repository file/line or test referenced in the audit.

How the kernel persists

Prime Agent exposes one built-in model tool: a persistent IPython kernel that keeps variables, imports, and functions across ordinary calls and compaction. File edits, shell commands, skills, and subagent calls are invoked through Python code. The kernel runs with your OS permissions and is not a security sandbox.

  • S008 supports the route's current claim set.
  • S007 supports the route's current claim set.
  • S012 supports the route's current claim set.
  • S013 supports the route's current claim set.

Host trust boundary

Everything here runs inside the local trust boundary. If a section mentions code execution, remember that process separation improves reliability and recovery more than it improves security.

Surviving compaction

Prime Agent exposes one built-in model tool: a persistent IPython kernel that keeps variables, imports, and functions across ordinary calls and compaction. File edits, shell commands, skills, and subagent calls are invoked through Python code. The kernel runs with your OS permissions and is not a security sandbox.

  • S008 supports the route's current claim set.
  • S007 supports the route's current claim set.
  • S012 supports the route's current claim set.
  • S013 supports the route's current claim set.

Kernel snapshots

Prime Agent exposes one built-in model tool: a persistent IPython kernel that keeps variables, imports, and functions across ordinary calls and compaction. File edits, shell commands, skills, and subagent calls are invoked through Python code. The kernel runs with your OS permissions and is not a security sandbox.

  • S008 supports the route's current claim set.
  • S007 supports the route's current claim set.
  • S012 supports the route's current claim set.
  • S013 supports the route's current claim set.

What this does not mean

This feature or concept does not imply a sandbox, a guarantee of success, or a claim that the harness is superior in every scenario. It only means the documented behavior exists in v0.7.1.