Two REPLs, One Port: What Agent-Plus-REPL Setups People Run, and Where the Keys Must Not Go

Table of Contents

A draft for the proposal shelf. Not submitted anywhere. Status: Submit first.

1. Pitch

Ninety-three Clojure repositories, two with delimiter repair. The agent gets the heap, not the keys.

2. Abstract

An agent that starts a process per question learns nothing between questions. One persistent nREPL shared by people and agents changes what can be checked, and raises a question most setups skip: which REPL may hold deploy credentials. This talk reports an audit of 93 Clojure repositories (nREPL or CIDER in 22, a CLAUDE.md in 20, a delimiter-repair hook in 2, clojure-lsp configuration in 1), a verification ladder whose gates were run against known-bad and known-good input, and the rule that keeps two REPLs on one port apart.

3. Audience, format, venue

Audience
Clojure developers using or evaluating coding agents.
Format
35 to 40 minutes; a 10-minute cut for Babashka Conf.
Where
Dutch Clojure Days, Clojure/conj, Babashka Conf.

4. Review

Both reviewers rate the evidence highest of the shelf; they differ on the room. The L7 review would submit this first, to Dutch Clojure Days. The presentation review calls agent-plus-REPL the most crowded slot of the year (Clojure/conj 2026 had a workshop, a showcase and two talks on it) and says the original abstract was four talks. This version keeps the two things nobody else has: the audit and the credential boundary. Open risks: say whose 93 repositories they are; and "gossip layer" is an analogy, so either show two agents redefining the same var or drop the framing.

5. Backing