fullauto.online

← Harnesses

Harness · spec sheet

Claude Code

Anthropic·coding
Category
Coding agent
Interface
Terminal, desktop, web, IDE
License
Proprietary (Anthropic)
Languages
Any (shell-driven)
Models
Claude Opus / Sonnet / Haiku
Isolation
Permissioned tools, opt-in sandbox
Best for
A coding agent with real permissions

Terminal, desktop, web and IDE. The reference implementation of a coding agent with real permissions.

What it is

Claude Code is Anthropic's own coding agent: a loop that reads your files, edits them, runs shell commands and reports back, pointed at whatever directory you started it in. It began as a terminal program and has since grown a desktop app, a web version and IDE extensions, but the terminal is still the reference surface and the one the others are measured against. The licence is proprietary — you get a binary and a documented configuration surface, not source.

It sits at the top of this board not because it writes better code than everything else. It runs the same Claude models anyone can call over the API, so the code quality is the model's. What is further along than most of the field is the unglamorous machinery around the model: permissions, context management, tool error messages, session resumption.

How the loop works

Search, read, edit, run, check. The agent gets a small set of sharp tools — file read and edit, glob, grep, shell, web fetch, plus anything you attach over MCP — rather than a large menu it has to shop from. It is expected to verify its own work by running the tests or the program rather than declaring success on the strength of a diff.

Three things extend that loop. A project file in the repository carries standing instructions the agent reads on every session, so conventions do not have to be re-explained. Subagents fan work out into their own context windows and report back a conclusion instead of a transcript. Compaction summarises the conversation when the window fills, which is what allows a session to run for an hour rather than twenty minutes. Hooks let you run your own commands at fixed points in the loop — the escape hatch for anything the vendor did not anticipate.

Isolation and permissions

The model in the spec above — permissioned tools with an opt-in sandbox — means each tool call is evaluated against rules you can edit and that persist across sessions: allow, ask, or deny. Read-only operations are typically allowed outright, writes and shell commands prompt, and you widen the allowlist as you learn what a given repository actually needs.

Be honest about what that buys you. A prompt is a speed bump, not a boundary, and a person approving their fortieth command of the afternoon is not really reading it. The sandbox is opt-in rather than default, which is the substantive difference from Codex CLI. Unsandboxed, the blast radius is the whole working directory plus whatever the shell can reach from it: credentials in the environment, the network, and any remote state your tooling is authenticated against. A disposable container or a git worktree costs little and removes the question.

Who it is for

Developers working in a real repository who want an agent that can actually run things, and teams already paying Anthropic. The per-repository setup — a project instructions file, a permission allowlist, a couple of hooks — is a few hours that pays back quickly. It is a poor fit if you need to switch model vendors per task, or if an audit requirement means you have to read the source of everything in the loop.

Limits

  • Claude only. The spec's model list is the whole list. There is no bring-your-own-model path; that is the trade you accept for the tight integration.
  • Proprietary. You cannot audit the loop, fork it, or pin a version indefinitely.
  • Cost tracks context, not tasks. An agent re-reading a large codebase each turn is expensive in a way that per-seat pricing intuitions do not prepare you for.
  • It still needs supervision. Long autonomous runs drift, and the failure mode is confident, plausible, wrong work that takes longer to review than to have written.
  • It moves fast. Surfaces and flags change between releases often enough that any dated write-up, including this one, should be checked against the docs.

Alternatives on this board

  • Codex CLI — open source and sandboxed by default, if those are hard requirements rather than preferences.
  • Claude Agent SDK — the same loop as a library, when you are building a product rather than sitting at a prompt.
  • Managed Agents — the same vendor, hosted, when you do not want to run session infrastructure.
  • OpenClaw and OpenCode — comparable ergonomics without the single-vendor model lock.

Sources

Hand-maintained editorial spec, not vendor copy — the read on each tool is judgement. Last checked 16 Sep 2026 · back to harnesses.