Reddit user SSShken's controlled second-account comparison claims Claude Code's machine-level plugins, skills, and MCP servers in the home directory inject instructions into every session regardless of account, so account-level isolation does not reset the agent's instruction surface; independent reproduction or an Anthropic response resolves it.
state: seedheat: lowuncertainty: mediumconvergesscott: highagent-harnesses claude-code context-injection
What is this?
A Reddit user (SSShken) reports that buying a second Claude account to get a clean, fair Claude Code comparison against Cursor and Codex failed: plugins, skills, and MCP servers configured at the machine level (the home-directory ~/.claude surface) inject instructions into every session regardless of which account is signed in, so account switching is not an isolation boundary. The supplied snippets independently corroborate the mechanism โ Anthropic's own issue tracker documents marketplace MCP instructions consuming 30โ55% of fresh-session context before any user input (claude-code #48680) and the Agent SDK's `settingSources: []` 'isolation mode' still loading user-level MCP servers and skills at ~35K tokens (#30304), while security write-ups confirm the global scope applies to every session regardless of directory and treat SKILL.md/MCP prose as live instruction channels. The snippets do not include the original post itself, so the poster's specific measurements rest on a single testimony source; and the framing is contested even in the tracker โ machine-scoped config is documented behavior, while unconditional instruction injection is filed as a bug requiring a separate fix.
Why it matters to Scott
Converges with his isolation doctrine โ principal-cell/runtime-containment already argue account identity is not an isolation boundary, and a harness he drives daily now demonstrates it: the real boundary is ~/.claude, so a 'fresh account' benchmark is still contaminated. The corroborating tracker numbers (marketplace MCP instructions consuming 30โ55% of fresh sessions; ~35K tokens even with settingSources: []) are dated receipts for his context-bloat and code-execution-beats-MCP arguments โ and they warn that his own cross-harness A/Bs (Claude Code vs Codex vs OpenCode) must pin the machine-level config surface or they benchmark the wrong unit.
dev:technology.claude-codeip:concept.principal-cellip:concept.context-bloatip:source.context-engineering-why-building-ai-agents-feels-like-programming-on-a-vic-20-again-ebookip:concept.model-plus-harness-benchmark-unitip:source.why-code-execution-beats-mcpradar:claude-code-nested-instruction-loadingradar:claude-projects-account-memory-defaultradar:claude-code-remote-attribution-injectionradar:blocks-mcp-cli-context-cost
queries asked of Scott's wikis
- claude code settings precedence harness configuration
- agent session baseline context overhead token budget
- coding agent comparison methodology clean environment
- instruction injection surface skills CLAUDE.md SKILL.md
- agent isolation machine vs account vs project scope
- MCP server instructions loaded every session startup
Measured heat
now 0 pts/hpeak 2 pts/hcomments 0/hpeers p0momentum: steady2 platformsage 482h
points/hour across evidence ยท reading as of 2026-10-12 02:59:37.977291+11:00 ยท deterministic, not a model opinion
How the heat travelled
pace: p42 vs 1032 stories at the 336h mark (now 482h old) โ ahead of agent-memory-add-search-evaluation (1.2x), behind agenticos-self-hosted-governance (0.9x)
Evidence (2) โ โญ canonical anchor
Interpretation history
2026-10-01T19:04:36Z
origin walked (opencode/cheap-glm, conf 0.85): anchor reddit.post.1wv51i1 -> echo.x.a4655ed053 by Artem Horobchenko (@SSShken)
2026-10-01T18:51:06Z
grounded: converges/high โ Converges with his isolation doctrine โ principal-cell/runtime-containment already argue account identity is not an isolation boundary, and a harness he drives
2026-10-01T18:42:40Z
case created โ Reproducible controlled-experiment claim about a distinct isolation failure (machine-level config surviving account resets) that no open case covers โ nested-instruction-loading is a different mechanism.
Decision trace
- 10-02 05:04promote_anchororigin walk conf 0.85
- 10-02 04:51groundConverges with his isolation doctrine โ principal-cell/runtime-containment already argue account identity is not an isolation boundary, and a harness he drives daily now demonstrates it: the real boun
- 10-02 04:42createReproducible controlled-experiment claim about a distinct isolation failure (machine-level config surviving account resets) that no open case covers โ nested-instruction-loading is a different mechani