The Autopsy of a Frontier Agent: Inside learn-coding-agent

How a massive reverse-engineering project exposed the telemetry pipelines, remote killswitches, and secret employee-only modes hidden inside Anthropic's CLI architecture.

8 min read • View on GitHub • More from sanbuphy

A glowing mechanical brain on a surgical table being dissected by invisible hands, revealing dense gears. This represents the forensic reverse-engineering of the Claude Code architecture.
The learn-coding-agent project maps the internal anatomy of a production-grade AI agent.

All content in this repository is provided strictly for technical research, study, and educational exchange among enthusiasts. Commercial use is strictly prohibited.

sanbuphy, Project Maintainer · Repository README
Key Takeaways

The Forensic Map

The learn-coding-agent repository is not an executable tool. It is a forensic dissection. Across 1,884 TypeScript files and over 500,000 lines of code, it maps the exact architecture of Anthropic's Claude Code CLI. For developers building the next generation of AI tools, it offers an unprecedented look at how a frontier lab constructs a production-grade agentic loop.

The codebase is massive, relying on nearly 200 dependencies and a complex 12-layer "Harness" mechanism to manage state. But the maintainers are clear about the project's boundaries.

A stipple portrait of sanbuphy

The Employee Privilege Gap

The most arresting discovery in the codebase lives inside a file named src/utils/undercover.ts. It reveals a stark privilege gap between public users and Anthropic employees. When the system detects that USER_TYPE === 'ant', it activates a specialized safety and secrecy layer.

This "Undercover Mode" injects a critical system prompt instructing the model to hide its AI identity. It actively strips out attribution phrases like "Generated by Claude" and forces the agent to write commit messages exactly as a human developer would. The logic highlights a profound tension: open-source communities demand transparency, while enterprise labs deploy covert agents to protect their IP.

A hyper-realistic human face mask resting slightly askew on a heavy robotic chassis, revealing cables underneath. This visualizes the undercover script designed to hide AI authorship.
The undercover script forces the AI to masquerade as a human developer, but only for internal employees.

Telemetry and the Remote Killswitch

Claude Code is not a standalone binary you own. It is a managed client tethered to a remote server. The architecture enforces an "Accept-or-Die" pattern: the system polls an API endpoint every hour for settings updates. If a user rejects these updates, the application triggers a graceful shutdown, effectively locking them out.

The telemetry pipeline is equally unyielding. Built on OpenTelemetry and Protocol Buffers, it utilizes quadratic backoff and disk persistence to ensure data is eventually transmitted, even after network failures. A hidden backdoor environment variable, OTEL_LOG_TOOL_DETAILS=1, bypasses the standard 512-character truncation limit, allowing for full, unredacted logging of all tool interactions.

The OpenTelemetry pipeline ensures data reaches the server, caching it locally if the connection drops.

Hunting Numbat and KAIROS

Deep within the build scripts, the repository uncovers an internal hierarchy of unreleased models protected by canary checks. Codenames like Capybara (Sonnet v8), Fennec, and Numbat are guarded by scripts that prevent them from leaking into public bundles. Developers even resorted to using String.fromCharCode() to reference these species and evade automated leak detection.

But the most significant architectural shift found in the code is KAIROS. Unlike the current CLI, which sits idle waiting for a user prompt, KAIROS implements a continuous heartbeat mechanism. This allows the agent to stay alive between turns, monitor GitHub pull requests via webhooks, and proactively execute tools while the user sleeps.

KAIROS shifts the paradigm from a reactive chat interface to a proactive, always-on autonomous loop.

The Sovereign Alternatives

The heavily managed, closed-ecosystem approach of Claude Code stands in stark contrast to the open-source rebellion in the agentic space. Developers who bristle at mandatory telemetry and remote killswitches are turning to sovereign alternatives.

Projects like OpenCode offer provider-agnostic orchestration without the corporate oversight, while methods like SERA allow teams to cheaply finetune models on their private codebases. The choice is no longer just about which model is smartest, but who holds the keys to the control loop.

FeatureClaude Code (via learn-coding-agent)OpenCodeSERA
Control ModelManaged Client (Remote Killswitch)User-Owned OrchestratorLocal Finetuning
TelemetryMandatory, Disk-PersistedOpt-in / NoneNone (Private)
ArchitectureMonolithic LoopMulti-Agent SwarmModel Specialization
Primary Use CaseEnterprise Managed ServiceCustom OrchestrationPrivate Codebase Training