
What happened
CoWorker security tech lead Ito described running CI-watch, parallel-review and overnight loops in Claude Code, and said auto mode's classifier halts after 3 consecutive or 20 cumulative blocks.
Why it matters
Auto mode covers the 'not stopping' half of a loop, but Ito says the 'not running wild' half hinges on rules, permissions and hooks, since the classifier is probabilistic and can let dangerous actions through.
What to watch
Whether teams write fail-closed PreToolUse and Stop hooks before trusting unattended runs; a Stop hook can only push back 8 times (CLAUDE_CODE_STOP_HOOK_BLOCK_CAP).
WHO IT HITSEngineering and platform teams running unattended coding agents on shared repositories are most exposed, because a single bad loop decision can destroy unreviewed work or touch production.
Summaries like this, in your inbox every morning.
Ito's account is drawn from daily practice rather than theory. He describes three loop shapes — CI/PR watching, parallel review and implementation, and scheduled overnight batches — and says that when a loop fails, it is almost always because one of six elements was vague: trigger, work, verification, waiting, exit condition, or the point at which a human is brought back in. Verification and human hand-back are the ones most often skipped.
A concrete example comes from writing the article itself. The classifier blocked an attempt to use non-public material in a public piece, and the decision went back to a human, who chose not to use it. Ito notes this shows the hand-back mechanism working, but also cautions that a block this time does not guarantee a block next time. He also describes how a broad instruction to "throw everything away" led auto mode to approve deleting untracked files, wiping the very logs the loop was writing — which is why loop logs and ledgers belong outside the working tree.
The practical stake is where each layer of defense sits. Ito ranks layers by how deterministic they are: classifier judgments are flexible but probabilistic, while permissions.deny and PreToolUse hooks are rigid but certain, and conversation-level approval can vanish when the chat is compressed. Whether a team's loops run unattended without incident is likely to depend on how much of the safety burden it moves down to those deterministic layers, and on whether it keeps a ledger of blocked and reverted actions and feeds them back into hooks.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Google said free Gemini app users will be restricted to the "Flash-Lite" model starting October 9; "Flash" nee…

Indie developer Robert Varadan argues that AI models like Opus 5.5 and GPT-6 Astra can clone game demos from a…

A developer published Rai, a small Rust engine that runs language models on an ordinary PC's CPU, using only t…

The developer published fk2000/minecraft-ai-bot, which uses Jev to assemble instructions, Gemini to pick from…

On September 22, 2026, Anthropic announced Claude Opus 5.5 at $4 input / $20 output per million tokens, then O…

A developer writing on Zenn compressed the full list of instructions he gives AI — intent, completion criteria…
