AppleScripting sandboxed app from another sandboxed app using ScriptingBridge

I'm trying to script a sandboxed app (which I wrote) from another sandboxed app using ScriptingBridge. I have access groups set up in the target app's sdef, and entitlements configured in the scripting app's sandbox entitlements. However, when I try to send Apple Events to the target (using ScriptingBridge), I see

warning: failed to get scripting definition from ~/<snip>/; it may not be scriptable.
logged in the console (the path to the target app is correct).

I've been able to reproduce the problem with a lightly modified version of the Sketch sample code app and a very simple test app that uses scripting bridge. I added
<access-group identifier="" access="rw"/>
to many elements in Sketch.sdef, as well as turned on sandboxing for Sketch.

Then, in my test app, I turned on sandboxing with the following entitlements:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "">
<plist version="1.0">

The app does the following:

#import "ViewController.h"
#import "Sketch.h"

@implementation ViewController
- (IBAction)draw:(id)sender {
SketchApplication *sketch = [SBApplication applicationWithBundleIdentifier:@""];
if (![sketch isKindOfClass:[NSClassFromString(@"SketchApplication") class]]) {
NSLog(@"Unable to get SketchApplication for Sketch");

Upon the call to
, the "warning: failed to get scripting definition" message is logged, and the object returned is an instance of
rather than a

If I turn off sandboxing in the test app, the error is not logged, and
returns a
as expected. The same is true if I add the
entitlement, though I believe this is unlikely to pass app store review.

Am I missing something beyond defining access groups in the target's sdef and adding the
entitlement? Does this work for anyone?

I've uploaded the test app and my modified Sketch projects here:

Answer Source

I filed a tech support incident with Apple about this, and they confirmed that it is a bug. The only workaround they suggested is to hold onto the (valid) instance of SketchApplication returned by the first call to -applicationWithBundleIdentifier: when Sketch is running for later use. This is not really a viable workaround at all in my particular case since the target app is very likely to already be running before the scripting app is launched.

The other option is to use the sandbox entitlement. I'll do that for now, and hope that I can justify its use for app store review.

I've filed a radar for this: rdar://27625862.