AIToday
Large Language ModelsAI Coding AssistantsZenn AI/MLPublished: Oct 4, 2026, 10:00 JST

Claude Code auto mode alone won't tame loops, CoWorker lead says

Claude Code auto mode alone won't tame loops, CoWorker lead says

3 Key Points

  1. What happened

    CoWorker security tech lead Ito described running CI-watch, parallel-review and overnight loops in Claude Code, and said auto mode's classifier halts after 3 consecutive or 20 cumulative blocks.

  2. Why it matters

    Auto mode covers the 'not stopping' half of a loop, but Ito says the 'not running wild' half hinges on rules, permissions and hooks, since the classifier is probabilistic and can let dangerous actions through.

  3. What to watch

    Whether teams write fail-closed PreToolUse and Stop hooks before trusting unattended runs; a Stop hook can only push back 8 times (CLAUDE_CODE_STOP_HOOK_BLOCK_CAP).

WHO IT HITSEngineering and platform teams running unattended coding agents on shared repositories are most exposed, because a single bad loop decision can destroy unreviewed work or touch production.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

Ito's account is drawn from daily practice rather than theory. He describes three loop shapes — CI/PR watching, parallel review and implementation, and scheduled overnight batches — and says that when a loop fails, it is almost always because one of six elements was vague: trigger, work, verification, waiting, exit condition, or the point at which a human is brought back in. Verification and human hand-back are the ones most often skipped.

A concrete example comes from writing the article itself. The classifier blocked an attempt to use non-public material in a public piece, and the decision went back to a human, who chose not to use it. Ito notes this shows the hand-back mechanism working, but also cautions that a block this time does not guarantee a block next time. He also describes how a broad instruction to "throw everything away" led auto mode to approve deleting untracked files, wiping the very logs the loop was writing — which is why loop logs and ledgers belong outside the working tree.

The practical stake is where each layer of defense sits. Ito ranks layers by how deterministic they are: classifier judgments are flexible but probabilistic, while permissions.deny and PreToolUse hooks are rigid but certain, and conversation-level approval can vanish when the chat is compressed. Whether a team's loops run unattended without incident is likely to depend on how much of the safety burden it moves down to those deterministic layers, and on whether it keeps a ledger of blocked and reverted actions and feeds them back into hooks.

FAQ
What happens if Claude Code's auto mode keeps blocking an action?
After 3 consecutive blocks, or 20 cumulative blocks in a session, auto mode pauses and reverts to prompting. The threshold is not configurable, so an unattended loop will stop there.
How long does a scheduled Claude Code loop actually run unattended?
A /loop stops when the terminal is closed, with no catch-up for missed rounds. Recurring tasks expire automatically after 7 days, and a session can hold at most 50 tasks.
Can rules reliably block dangerous commands like force push?
Ito warns that permission rules match only the literal string prefix, so git push -f or git push --force-with-lease slip past a Bash(git push --force *) deny rule. Enforcing branch protection in the repository is the reliable fix.

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleBlackRock: stablecoins to power AI agent payments