The session runner starts child processes, which are separate copies of Claude Code doing the work. It now writes three kinds of instruction text to files instead of passing them as command-line text:
system-prompt
append-system-prompt
append-subagent-system-prompt
The files are named like remote-system-prompt.txt and use file permission mode 384, readable and writable only by their owner. The child receives a matching --<key>-file option. The subagent prompt still goes on the command line only when the child is not the runner's own program and every piece is under 131072 bytes.
Why
In practice, instruction text for remote sessions travels in private files rather than in the command that starts each process.
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's release notes agreeImproved screen-reader output in /mcp: a disabled server is read as "off" instead of "pending"