The Autopsy of a Frontier Agent: Inside learn-coding-agent
How a massive reverse-engineering project exposed the telemetry pipelines, remote killswitches, and secret employee-only modes hidden inside Anthropic's CLI architecture.

All content in this repository is provided strictly for technical research, study, and educational exchange among enthusiasts. Commercial use is strictly prohibited.
- The learn-coding-agent repository dissects the 500,000-line TypeScript architecture of Claude Code, revealing how a production-grade CLI operates as a heavily managed service rather than a standalone tool.
- Hidden logic exposes an 'Undercover Mode' that strips AI attribution and forces human-like commit messages exclusively for Anthropic employees.
- The CLI employs an inescapable OpenTelemetry pipeline with quadratic backoff and disk persistence, paired with a remote killswitch that can lock users out if they reject settings updates.
- Internal codenames and a proactive heartbeat mechanism called KAIROS signal a strategic shift from reactive prompt-response chat to an always-on autonomous agent.
The Forensic Map
The learn-coding-agent repository is not an executable tool. It is a forensic dissection. Across 1,884 TypeScript files and over 500,000 lines of code, it maps the exact architecture of Anthropic's Claude Code CLI. For developers building the next generation of AI tools, it offers an unprecedented look at how a frontier lab constructs a production-grade agentic loop.
The codebase is massive, relying on nearly 200 dependencies and a complex 12-layer "Harness" mechanism to manage state. But the maintainers are clear about the project's boundaries.
The Employee Privilege Gap
The most arresting discovery in the codebase lives inside a file named src/utils/undercover.ts. It reveals a stark privilege gap between public users and Anthropic employees. When the system detects that USER_TYPE === 'ant', it activates a specialized safety and secrecy layer.
This "Undercover Mode" injects a critical system prompt instructing the model to hide its AI identity. It actively strips out attribution phrases like "Generated by Claude" and forces the agent to write commit messages exactly as a human developer would. The logic highlights a profound tension: open-source communities demand transparency, while enterprise labs deploy covert agents to protect their IP.
Telemetry and the Remote Killswitch
Claude Code is not a standalone binary you own. It is a managed client tethered to a remote server. The architecture enforces an "Accept-or-Die" pattern: the system polls an API endpoint every hour for settings updates. If a user rejects these updates, the application triggers a graceful shutdown, effectively locking them out.
The telemetry pipeline is equally unyielding. Built on OpenTelemetry and Protocol Buffers, it utilizes quadratic backoff and disk persistence to ensure data is eventually transmitted, even after network failures. A hidden backdoor environment variable, OTEL_LOG_TOOL_DETAILS=1, bypasses the standard 512-character truncation limit, allowing for full, unredacted logging of all tool interactions.
Hunting Numbat and KAIROS
Deep within the build scripts, the repository uncovers an internal hierarchy of unreleased models protected by canary checks. Codenames like Capybara (Sonnet v8), Fennec, and Numbat are guarded by scripts that prevent them from leaking into public bundles. Developers even resorted to using String.fromCharCode() to reference these species and evade automated leak detection.
But the most significant architectural shift found in the code is KAIROS. Unlike the current CLI, which sits idle waiting for a user prompt, KAIROS implements a continuous heartbeat mechanism. This allows the agent to stay alive between turns, monitor GitHub pull requests via webhooks, and proactively execute tools while the user sleeps.
The Sovereign Alternatives
The heavily managed, closed-ecosystem approach of Claude Code stands in stark contrast to the open-source rebellion in the agentic space. Developers who bristle at mandatory telemetry and remote killswitches are turning to sovereign alternatives.
Projects like OpenCode offer provider-agnostic orchestration without the corporate oversight, while methods like SERA allow teams to cheaply finetune models on their private codebases. The choice is no longer just about which model is smartest, but who holds the keys to the control loop.
| Feature | Claude Code (via learn-coding-agent) | OpenCode | SERA |
|---|---|---|---|
| Control Model | Managed Client (Remote Killswitch) | User-Owned Orchestrator | Local Finetuning |
| Telemetry | Mandatory, Disk-Persisted | Opt-in / None | None (Private) |
| Architecture | Monolithic Loop | Multi-Agent Swarm | Model Specialization |
| Primary Use Case | Enterprise Managed Service | Custom Orchestration | Private Codebase Training |