while (true) {
a ctx = assemble(history, memory, tools)
b out = model(ctx)
if (out.isTextOnly())
stopped = run_stop_hooks(out) # 可否决
c res = execute(out.toolUse)
history.push(res)
}
新兴的 AI 监管为实现 Anthropic/operator/user 权限层级的架构添加了外部约束。欧盟委员会的 GPAI 行为准则与实施指南,说明通用 AI 治理正在朝对文档、风险管理、透明度与监督的更明确期待推进。MIT AI Agent Index 发现只有 13.3% 的已索引 agentic 系统发布 agent 专属安全卡。
Bartz v. Anthropic PBC, no. 3:24-cv-05417-WHA. U.S. District Court for the Northern District of California, Order on Motion for Summary Judgment (June 23, 2025), Alsup, J. Court docket: https://www.courtlistener.com/docket/ 69058235/bartz-v-anthropic-pbc/, 2025.
Michael Ahn, Anthony Brohan, Noah Brown, Yevgen Chebotar, Omar Cortes, Byron David, Chelsea Finn, Chuyuan Fu, Keerthana Gopalakrishnan, Karol Hausman, et al. Do as i can, not as i say: Grounding language in robotic affordances. arXiv preprint arXiv:2204.01691, 2022.
Aizierjiang Aiersilan. The vibe-check protocol: Quantifying cognitive offloading in ai programming. arXiv preprint arXiv:2601.02410, 2026.
Anthropic. Our framework for developing safe and trustworthy agents. https://www.anthropic.com/news/ our-framework-for-developing-safe-and-trustworthy-agents, 2025a.
Anthropic. Orchestrate subagents at scale with dynamic workflows. Claude Code Documentation, https://code.claude. com/docs/en/workflows, 2026i. Research preview; requires Claude Code v2.1.154 or later.
Shraddha Barke, Michael B James, and Nadia Polikarpova. Grounded copilot: How programmers interact with code-generating models. Proceedings of the ACM on Programming Languages, 7(OOPSLA1):85–111, 2023.
Elad Beber. InversePrompt: Turning claude against itself, one prompt at a time. https://cymulate.com/blog/ cve-2025-547954-54795-claude-inverseprompt/, 2025. CVE-2025-54794, CVE-2025-54795; updated April 6, 2026.
Joel Becker, Nate Rush, Elizabeth Barnes, and David Rein. Measuring the impact of early-2025 ai on experienced open-source developer productivity. arXiv preprint arXiv:2507.09089, 2025.
Joeran Beel, Min-Yen Kan, and Moritz Baumgart. Evaluating sakana’s ai scientist: Bold claims, mixed results, and a promising future? In ACM SIGIR Forum, volume 59, pages 1–20. ACM New York, NY, USA, 2025.
Yoshua Bengio, Stephen Clare, Carina Prunkl, Maksym Andriushchenko, Ben Bucknall, Malcolm Murray, Rishi Bommasani, Stephen Casper, Tom Davidson, Raymond Douglas, et al. International ai safety report 2026. arXiv preprint arXiv:2602.21012, 2026.
Piercosma Bisconti, Matteo Prandi, Federico Pierucci, Federico Sartore, Enrico Panai, Laura Caroli, Yue Zhu, Adam Leon Smith, Luca Nannini, Marcello Galisai, et al. Boiling the frog: A multi-turn benchmark for agentic safety. arXiv preprint arXiv:2605.22643, 2026.
Johan Bjorck, Fernando Castañeda, Nikita Cherniadev, Xingye Da, Runyu Ding, Linxi Fan, Yu Fang, Dieter Fox, Fengyuan Hu, Spencer Huang, et al. Gr00t n1: An open foundation model for generalist humanoid robots. arXiv preprint arXiv:2503.14734, 2025.
Kevin Black, Noah Brown, Danny Driess, Adnan Esmail, Michael Equi, Chelsea Finn, Niccolo Fusai, Lachy Groom, Karol Hausman, Brian Ichter, et al. π0 : A vision-language-action flow model for general robot control. arXiv preprint arXiv:2410.24164, 2024.
Anthony Brohan, Noah Brown, Justice Carbajal, Yevgen Chebotar, Xi Chen, Krzysztof Choromanski, Tianli Ding, Danny Driess, Avinava Dubey, Chelsea Finn, et al. Rt-2: Vision-language-action models transfer web knowledge to robotic control. arXiv preprint arXiv:2307.15818, 2023.
Yuandao Cai, Yuzhang Zhu, Liyou Gao, Wensheng Tang, and Shengchao Qin. Push your agent: Measuring and enforcing quantitative goal persistence in long-horizon LLM agents. 2026. https://arxiv.org/abs/2605.23574.
Mert Cemri, Melissa Z Pan, Shuyi Yang, Lakshya A Agrawal, Bhavya Chopra, Rishabh Tiwari, Kurt Keutzer, Aditya
Parameswaran, Dan Klein, Kannan Ramchandran, et al. Why do multi-agent llm systems fail? arXiv preprint
Mark Chen, Jerry Tworek, Heewoo Jun, Qiming Yuan, Henrique Ponde De Oliveira Pinto, Jared Kaplan, Harri
Edwards, Yuri Burda, Nicholas Joseph, Greg Brockman, et al. Evaluating large language models trained on code.
arXiv preprint arXiv:2107.03374, 2021.
Valerie Chen, Alan Zhu, Sebastian Zhao, Hussein Mozannar, David Sontag, and Ameet Talwalkar. Need help? designing proactive ai assistants for programming. In Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems, pages 1–18, 2025.
Hung, Chen Qian, et al. Agentverse: Facilitating multi-agent collaboration and exploring emergent behaviors. In
The Twelfth International Conference on Learning Representations, 2023.
Boris Cherny and Cat Wu. Claude code: Anthropic’s agent in your terminal. Latent Space podcast, https://www. latent.space/p/claude-code, 2025.
Prateek Chhikara, Dev Khant, Saket Aryan, Taranjeet Singh, and Deshraj Yadav. Mem0: Building production-ready ai agents with scalable long-term memory. arXiv preprint arXiv:2504.19413, 2025.
Musa Cim, Burak Topcu, Chita Das, and Mahmut Taylan Kandemir. Parallel context compaction for long-horizon llm
Luca Compagna. Claude fable 5, take two: Same model, different harness, and a very different result. Endor Labs, https: //www.endorlabs.com/learn/claude-fable-5-take-two-same-model-different-harness-and-a-very-different-result, 2026.
Cursor. Cursor: The best way to code with AI. https://cursor.com/, 2026. Official product website. Accessed April 12, 2026.
Fabrizio Dell’Acqua, Charles Ayoubi, Hila Lifshitz, Raffaella Sadun, Ethan Mollick, Lilach Mollick, Yi Han, Jeff Goldman, Hari Nair, Stewart Taub, et al. The cybernetic teammate: A field experiment on generative ai reshaping teamwork and expertise. Technical report, National Bureau of Economic Research, 2025.
Yang Deng, Lizi Liao, Wenqiang Lei, Grace Hui Yang, Wai Lam, and Tat-Seng Chua. Proactive conversational ai: A comprehensive survey of advancements and opportunities. ACM Transactions on Information Systems, 43(3):1–45, 2025.
Shuangrui Ding, Xuanlang Dai, Long Xing, Shengyuan Ding, Ziyu Liu, Yang JingYi, Penghui Yang, Zhixiong Zhang, Xilin Wei, Xinyu Fang, et al. Wildclawbench: A benchmark for real-world, long-horizon agent evaluation. arXiv preprint arXiv:2605.10912, 2026.
Aviv Donenfeld and Oded Vanunu. Caught in the hook: RCE and API token ex- filtration through Claude Code project files. https://research.checkpoint.com/2026/ rce-and-api-token-exfiltration-through-claude-code-project-files-cve-2025-59536/, 2026. CVE-2025-59536 (CVSS 8.7), CVE-2026-21852 (CVSS 5.3).
Yilun Du, Shuang Li, Antonio Torralba, Joshua B Tenenbaum, and Igor Mordatch. Improving factuality and reasoning in language models through multiagent debate. In Forty-first international conference on machine learning, 2024.
European Commission. Guidelines on the scope of obligations for providers of general- purpose AI models under the AI act. https://digital-strategy.ec.europa.eu/en/library/ guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act, 2025b. Official EU Commis- sion guideline document.
Figure AI. Helix: A vision-language-action model for generalist humanoid control. https://www.figure.ai/news/helix, 2025. Figure AI technical blog.
David Garlan, Mary Shaw, et al. An introduction to software architecture. Advances in software engineering and knowledge engineering, 1(3.4), 1993.
Paul Gauthier. Aider: AI pair programming in your terminal, 2024. https://github.com/Aider-AI/aider. Open-source software, https://aider.chat.
Google. Build with Google antigravity, our new agentic development platform. Google Developers Blog, https:
//developers.googleblog.com/build-with-google-antigravity-our-new-agentic-development-platform/, 2025. Ac- cessed June 2026.
Juraj Gottweis, Wei-Hung Weng, Alexander Daryin, Tao Tu, Anil Palepu, Petar Sirkovic, Artiom Myaskovsky, Felix Weissenberger, Keran Rong, Ryutaro Tanno, et al. Towards an ai co-scientist. arXiv preprint arXiv:2502.18864, 2025.
Taicheng Guo, Xiuying Chen, Yaqi Wang, Ruidi Chang, Shichao Pei, Nitesh V Chawla, Olaf Wiest, and Xian- gliang Zhang. Large language model based multi-agents: A survey of progress and challenges. arXiv preprint arXiv:2402.01680, 2024.
Hao He, Courtney Miller, Shyam Agarwal, Christian Kästner, and Bogdan Vasilescu. Speed at the cost of quality: How cursor ai increases short-term velocity and long-term complexity in open-source projects. arXiv preprint
arXiv:2511.04427, 2025.
Zeyu He, Hannah Kim, Dan Zhang, and Estevam Hruschka. How to steer your multi-agent system: Human-llm collaborative planning. In Proceedings of the ACM Conference on AI and Agentic Systems, pages 330–347, 2026.
Sirui Hong, Mingchen Zhuge, Jonathan Chen, Xiawu Zheng, Yuheng Cheng, Jinlin Wang, Ceyao Zhang, Zili Wang, Steven Ka Shing Yau, Zijuan Lin, et al. Metagpt: Meta programming for a multi-agent collaborative framework. In The twelfth international conference on learning representations, 2023.
Xinyi Hou, Yanjie Zhao, Shenao Wang, and Haoyu Wang. Model context protocol (mcp): Landscape, security threats, and future research directions. ACM Transactions on Software Engineering and Methodology, 2025.
Shengran Hu, Cong Lu, and Jeff Clune. Automated design of agentic systems. arXiv preprint arXiv:2408.08435, 2024.
Yuyang Hu, Shichun Liu, Yanwei Yue, Guibin Zhang, Boyang Liu, Fangyi Zhu, Jiahang Lin, Honglin Guo, Shihan Dou, Zhiheng Xi, et al. Memory in the age of ai agents. arXiv preprint arXiv:2512.13564, 2025.
Saffron Huang, Bryan Seethor, Esin Durmus, Kunal Handa, Miles McCain, Michael Stern, and Deep Gan- guli. How AI is transforming work at Anthropic. Anthropic Research Blog, https://anthropic.com/research/ how-ai-is-transforming-work-at-anthropic, 2025.
Wei-Chieh Huang, Weizhi Zhang, Yueqing Liang, Yuanchen Bei, Yankai Chen, Tao Feng, Xinyu Pan, Zhen Tan
Yu Wang, Tianxin Wei, et al. Rethinking memory mechanisms of foundation agents in the second half. arXiv
preprint arXiv:2602.06052, 2026.
John Hughes. Claude Code auto mode: A safer way to skip permissions. Anthropic Engineering, https://www. anthropic.com/engineering/claude-code-auto-mode, 2026.
Carlos E Jimenez, John Yang, Alexander Wettig, Shunyu Yao, Kexin Pei, Ofir Press, and Karthik Narasimhan. Swe-bench: Can language models resolve real-world github issues? arXiv preprint arXiv:2310.06770, 2023.
Sayash Kapoor, Benedikt Stroebl, Zachary S Siegel, Nitya Nadgir, and Arvind Narayanan. Ai agents that matter. arXiv preprint arXiv:2407.01502, 2024.
Andrej Karpathy. [1hr talk] intro to large language models. YouTube talk, https://www.youtube.com/watch?v= zjkBMFhNj_g, 2023. November 2023; popularizes the LLM-as-OS framing.
Haq, Ashutosh Sharma, Thomas T Joshi, Hanna Moazam, et al. Dspy: Compiling declarative language model calls
into self-improving pipelines. arXiv preprint arXiv:2310.03714, 2023.
Nataliya Kosmyna, Eugene Hauptmann, Ye Tong Yuan, Jessica Situ, Xian-Hao Liao, Ashly Vivian Beresnitzky, Iris Braunstein, and Pattie Maes. Your brain on chatgpt: Accumulation of cognitive debt when using an ai assistant for essay writing task. arXiv preprint arXiv:2506.08872, 4, 2025.
Thomas Kwa, Ben West, Joel Becker, Amy Deng, Katharyn Garcia, Max Hasin, Sami Jawhar, Megan Kinniment, Nate Rush, Sydney Von Arx, et al. Measuring ai ability to complete long software tasks. In The Thirty-ninth Annual
Conference on Neural Information Processing Systems.
LangChain. Managed deep agents: the fastest way to ship a production deep agent. LangChain Blog, https: //www.langchain.com/blog/introducing-managed-deep-agents, 2026b.
LangChain, Inc. LangGraph: Build resilient language agents as graphs, 2024. https://github.com/langchain-ai/ langgraph. GitHub repository.
Geonsun Lee, Min Xia, Nels Numan, Xun Qian, David Li, Yanhe Chen, Achin Kulshrestha, Ishan Chatterjee, Yinda Zhang, Dinesh Manocha, et al. Sensible agent: A framework for unobtrusive interaction with proactive ar agents. In Proceedings of the 38th Annual ACM Symposium on User Interface Software and Technology, pages 1–22, 2025.
Guohao Li, Hasan Hammoud, Hani Itani, Dmitrii Khizbullin, and Bernard Ghanem. Camel: Communicative agents for" mind" exploration of large language model society. Advances in neural information processing systems, 36: 51991–52008, 2023.
Tian Liang, Zhiwei He, Wenxiang Jiao, Xing Wang, Yan Wang, Rui Wang, Yujiu Yang, Shuming Shi, and Zhaopeng Tu. Encouraging divergent thinking in large language models through multi-agent debate. In Proceedings of the 2024 conference on empirical methods in natural language processing, pages 17889–17904, 2024.
Xingyu Bruce Liu, Shitao Fang, Weiyan Shi, Chien-Sheng Wu, Takeo Igarashi, and Xiang’Anthony’ Chen. Proactive conversational agents with inner thoughts. In Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems, pages 1–19, 2025.
Yue Liu, Ratnadira Widyasari, Yanjie Zhao, Ivana Clairine Irsan, and David Lo. Debt behind the ai boom: A large-scale empirical study of ai-generated code in the wild. arXiv preprint arXiv:2603.28592, 2026.
Chris Lu, Cong Lu, Robert Tjarko Lange, Jakob Foerster, Jeff Clune, and David Ha. The ai scientist: Towards fully automated open-ended scientific discovery. arXiv preprint arXiv:2408.06292, 2024.
Miles McCain, Thomas Millar, Saffron Huang, Jake Eaton, Kunal Handa, Michael Stern, Alex Tamkin, Matt Kearney, Esin Durmus, Judy Shen, Jerry Hong, Brian Calvert, Jun Shern Chan, Francesco Mosconi, David Saunders, Tyler Neylon, Gabriel Nicholas, Sarah Pollack, Jack Clark, and Deep Ganguli. Measuring AI agent autonomy in practice. Anthropic Research Blog, https://anthropic.com/research/measuring-agent-autonomy, 2026.
Ethan Mollick. Co-intelligence: Living and working with AI. Penguin, 2024.
Luca Nannini, Adam Leon Smith, Michele Joshua Maggini, Enrico Panai, Sandra Feliciano, Aleksandr Tiulkanov, Elena Maran, James Gealy, and Piercosma Bisconti. Ai agents under eu law. arXiv preprint arXiv:2604.04604, 2026.
National Security Agency. Model context protocol (MCP): Security design considerations for AI-driven automation. Technical Report PP-26-1834, National Security Agency, May 2026. https://www.nsa.gov/Portals/75/documents/ Cybersecurity/CSI_MCP_SECURITY.pdf.
Alexander Novikov, Ngân Vũ, Marvin Eisenberger, Emilien Dupont, Po-Sen Huang, Adam Zsolt Wagner, Sergey Shirobokov, Borislav Kozlovskii, Francisco JR Ruiz, Abbas Mehrabian, et al. Alphaevolve: A coding agent for scientific and algorithmic discovery. arXiv preprint arXiv:2506.13131, 2025.
OECD. Governing with artificial intelligence: The state of play and way forward in core government functions. https:
Gil Pasternak, Dheeraj Rajagopal, Julia White, Dhruv Atreja, Matthew Thomas, George Hurn-Maloney, and Ash Lewis. Beyond reactivity: Measuring proactive problem solving in llm agents. arXiv preprint arXiv:2510.19771, 2025.
Divya Pathak, Harshit Kumar, Anuska Roy, Felix George, Mudit Verma, and Pratibha Moogi. Detecting silent failures in multi-agentic ai trajectories. arXiv preprint arXiv:2511.04032, 2025.
Neil Perry, Megha Srivastava, Deepak Kumar, and Dan Boneh. Do users write more insecure code with ai assistants? In Proceedings of the 2023 ACM SIGSAC conference on computer and communications security, pages 2785–2799, 2023.
Kevin Pu, Daniel Lazaro, Ian Arawjo, Haijun Xia, Ziang Xiao, Tovi Grossman, and Yan Chen. Assistance or disruption? exploring and evaluating the design and trade-offs of proactive ai programming support. In Proceedings of the 2025
CHI conference on human factors in computing systems, pages 1–21, 2025.
Chen Qian, Wei Liu, Hongzhang Liu, Nuo Chen, Yufan Dang, Jiahao Li, Cheng Yang, Weize Chen, Yusheng Su, Xin Cong, et al. Chatdev: Communicative agents for software development. In Proceedings of the 62nd annual meeting of the association for computational linguistics (volume 1: Long papers), pages 15174–15186, 2024.
Gwendolyn Rak. How to stay ahead of AI as an early-career engineer. IEEE Spectrum, 2025. https://spectrum.ieee.
org/ai-effect-entry-level-jobs.
Charles Reis and Steven D Gribble. Isolating web programs in modern browser architectures. In Proceedings of the 4th ACM European conference on Computer systems, pages 219–232, 2009.
Ravi S Sandhu, Edward J Coyne, Hal L Feinstein, and Charles E Youman. Role-based access control models. Computer, 29(2):38–47, 2002.
Timo Schick, Jane Dwivedi-Yu, Roberto Dessì, Roberta Raileanu, Maria Lomeli, Eric Hambro, Luke Zettlemoyer, Nicola Cancedda, and Thomas Scialom. Toolformer: Language models can teach themselves to use tools. Advances in neural information processing systems, 36:68539–68551, 2023.
Erik Schluntz and Barry Zhang. Building effective agents. Anthropic Research, https://www.anthropic.com/research/ building-effective-agents, 2024.
Judy Hanwen Shen and Alex Tamkin. How ai impacts skill formation. arXiv preprint arXiv:2601.20245, 2026.
Noah Shinn, Federico Cassano, Ashwin Gopinath, Karthik Narasimhan, and Shunyu Yao. Reflexion: Language agents with verbal reinforcement learning. Advances in neural information processing systems, 36:8634–8652, 2023.
Leon Staufer, Kevin Feng, Kevin Wei, Luke Bailey, Yawen Duan, Mick Yang, A Pinar Ozisik, Stephen Casper, and Noam Kolt. The 2025 ai agent index: Documenting technical and safety features of deployed agentic ai systems. arXiv preprint arXiv:2602.17753, 2026.
Peter Steinberger and OpenClaw Contributors. OpenClaw: Personal AI assistant. https://github.com/openclaw/ openclaw, 2026. Open-source multi-channel AI assistant gateway. MIT License.
Viktoria Stray, Elias Goldmann Brandtzæg, Viggo Tellefsen Wivestad, Astri Barbala, and Nils Brede Moe. Devel- oper productivity with and without github copilot: A longitudinal mixed-methods case study. arXiv preprint arXiv:2509.20353, 2025.
Yifan Sui, Han Zhao, Rui Ma, Zhiyuan He, Hao Wang, Jianxun Li, and Yuqing Yang. Act while thinking: Accelerating llm agents via pattern-aware speculative tool execution. arXiv preprint arXiv:2603.18897, 2026.
Weiwei Sun, Xuhui Zhou, Weihua Du, Xingyao Wang, Sean Welleck, Graham Neubig, Maarten Sap, and Yiming Yang.
Training proactive and personalized llm agents. arXiv preprint arXiv:2511.02208, 2025.
The Linux Foundation. Linux foundation announces the formation of the agentic AI founda- tion (AAIF), anchored by new project contributions including model context protocol (MCP), goose and AGENTS.md. Linux Foundation Press Release, 2025. https://www.linuxfoundation.org/press/ linux-foundation-announces-the-formation-of-the-agentic-ai-foundation.
Priyansh Trivedi and Olivier Schmitt. Does code cleanliness affect coding agents? a controlled minimal-pair study. arXiv preprint arXiv:2605.20049, 2026.
Janelle Teng Wade, Lance Co Ting Keh, Talia Goldberg, David Cowan, Grace Ma, Bhavik Nagda, Brandon Nydick, and Bar Weiner. AI infrastructure roadmap: Five frontiers for 2026. Bessemer Venture Partners, https://www.bvp. com/atlas/ai-infrastructure-roadmap-five-frontiers-for-2026, 2026.
Guanzhi Wang, Yuqi Xie, Yunfan Jiang, Ajay Mandlekar, Chaowei Xiao, Yuke Zhu, Linxi Fan, and Anima Anandkumar. Voyager: An open-ended embodied agent with large language models. arXiv preprint arXiv:2305.16291, 2023.
Lei Wang, Chen Ma, Xueyang Feng, Zeyu Zhang, Hao Yang, Jingsen Zhang, Zhiyuan Chen, Jiakai Tang, Xu Chen, Yankai Lin, et al. A survey on large language model based autonomous agents. Frontiers of Computer Science, 18 (6):186345, 2024a.
Xingyao Wang, Boxuan Li, Yufan Song, Frank F Xu, Xiangru Tang, Mingchen Zhuge, Jiayi Pan, Yueqi Song, Bowen Li, Jaskirat Singh, et al. Openhands: An open platform for ai software developers as generalist agents. arXiv preprint arXiv:2407.16741, 2024b.
Zora Zhiruo Wang, Jiayuan Mao, Daniel Fried, and Graham Neubig. Agent workflow memory. arXiv preprint arXiv:2409.07429, 2024c.
Michael Wooldridge. An introduction to multiagent systems. John Wiley & Sons, 2009.
Qingyun Wu, Gagan Bansal, Jieyu Zhang, Yiran Wu, Beibin Li, Erkang Zhu, Li Jiang, Xiaoyun Zhang, Shaokun Zhang, Jiale Liu, et al. Autogen: Enabling next-gen llm applications via multi-agent conversations. In First conference on language modeling, 2024.
Qing Xiao, Xinlan Emily Hu, Mark E Whiting, Arvind Karunakaran, Hong Shen, and Hancheng Cao. Ai hasn’t fixed teamwork, but it shifted collaborative culture: A longitudinal study in a project-based software development organization (2023-2025). arXiv preprint arXiv:2509.10956, 2025.
Bin Xu. Ai agent systems: Architectures, applications, and evaluation. arXiv preprint arXiv:2601.01743, 2026.
Wujiang Xu, Zujie Liang, Kai Mei, Hang Gao, Juntao Tan, and Yongfeng Zhang. A-mem: Agentic memory for llm
agents. arXiv preprint arXiv:2502.12110, 2025.
Wujiang Xu, Yu Wang, Kai Mei, Kaiqu Liang, Zhenting Wang, Mingyu Jin, Han Zhang, Shi-Xiong Zhang, Wenyue Hua
Sambit Sahu, et al. Memgym: a long-horizon memory environment for llm agents. arXiv preprint arXiv:2605.20833
2026.
John Yang, Carlos E Jimenez, Alexander Wettig, Kilian Lieret, Shunyu Yao, Karthik Narasimhan, and Ofir Press. Swe-agent: Agent-computer interfaces enable automated software engineering. Advances in Neural Information Processing Systems, 37:50528–50652, 2024.
Shunyu Yao, Jeffrey Zhao, Dian Yu, Nan Du, Izhak Shafran, Karthik R Narasimhan, and Yuan Cao. React: Synergizing reasoning and acting in language models. In The eleventh international conference on learning representations, 2022.
Shunyu Yao, Noah Shinn, Pedram Razavi, and Karthik Narasimhan. τ -bench: A benchmark for tool-agent-user interaction in real-world domains. arXiv preprint arXiv:2406.12045, 2024.
Qizheng Zhang, Changran Hu, Shubhangi Upasani, Boyuan Ma, Fenglu Hong, Vamsidhar Kamanuru, Jay Rainton, Chen Wu, Mengmeng Ji, Hanchen Li, et al. Agentic context engineering: Evolving contexts for self-improving language models. arXiv preprint arXiv:2510.04618, 2025a.
Zeyu Zhang, Quanyu Dai, Xiaohe Bo, Chen Ma, Rui Li, Xu Chen, Jieming Zhu, Zhenhua Dong, and Ji-Rong Wen. A survey on the memory mechanism of large language model-based agents. ACM Transactions on Information Systems, 43(6):1–47, 2025b.
Andy Zhou, Kai Yan, Michal Shlapentokh-Rothman, Haohan Wang, and Yu-Xiong Wang. Language agent tree search unifies reasoning acting and planning in language models. arXiv preprint arXiv:2310.04406, 2023.
Mingchen Zhuge, Wenyi Wang, Louis Kirsch, Francesco Faccio, Dmitrii Khizbullin, and Jürgen Schmidhuber. Gptswarm: Language agents as optimizable graphs. In Forty-first International Conference on Machine Learning, 2024.
Appendix
Evidence Base and Methodology
This appendix records the evidence sources, analytic procedure, and limits of the study.
Evidence Base and Evidence Tiers
Claims in this paper are grounded at three evidence tiers: • Tier A (product-documented): Claims drawn from official Anthropic documentation and engineering publications. These establish product intent but may not reflect internal implementation. • Tier B (code-verified): Claims citing specific files and functions in the extracted TypeScript codebase (v2.1.88, obtained from a publicly available npm package extraction). This is the strongest evidence tier. • Tier C (reconstructed): Claims derived from community analysis, OpenClaw or Hermes Agent structural comparison, or inference from code patterns. These are stated with hedging language.
The source corpus comprises approximately 1,884 files totaling roughly 512K lines of TypeScript. OpenClaw
and Hermes Agent are used as comparative reference points rather than as ground-truth standards.
Design-Space Analytic Procedure
Design questions were identified by examining each subsystem for recurring choice points where alternative
designs exist in other production agents. Claude Code’s answers to each question were traced through specific
source files and function implementations (Tier B evidence). The five-value framework (human decision
authority, safety, security, and privacy, reliable execution, capability amplification, and contextual adaptability)
was identified from official documentation and creator statements (Tier A), then traced through thirteen
design principles to architectural decisions. Long-term capability preservation is treated separately as a
cross-cutting question rather than a design value, because it is not prominently reflected as a design driver
in the architecture or in Anthropic’s stated values (Section 2.4). Token economics serves as a cross-cutting
constraint that bounds all five values simultaneously, revealing how individual subsystem choices interact
under shared resource pressure.
Limitations • Static snapshot. Analysis reflects one version (v2.1.88). Feature flags (e.g., TRANSCRIPT_CLASSI- FIER, CONTEXT_COLLAPSE) create build-time variability. Different build targets may produce functionally different applications. • Reverse-engineering epistemology. Source code reveals implemented structure, control flow, dependencies, and feature gates. It cannot confirm design intent, enabled production flags, runtime prevalence, or unshipped behavior. • Single-system analysis. Findings describe Claude Code’s design space, not the entire design space of coding agents. Generalizations are bounded. • Comparison-system snapshots. The OpenClaw and Hermes Agent analyses each reflect a specific development state and may not represent their current capabilities.
Package Structure
This part maps the main TypeScript package to runtime responsibilities.
Directory-to-Responsibility Map
The package (Figure 9) is organized around a src/ directory. Table 7 lists the key files that form the main
subsystems.
Table 7 Key files by approximate size and runtime responsibility. File Size Responsibility main.tsx 804KB Entry point, mode dispatch, setup query.ts 68KB Core agent loop, 5 context shapers QueryEngine.ts 47KB SDK/headless conversation wrapper Tool.ts 30KB Tool interface, types, utilities history.ts 14KB Global prompt history mcp/client.ts Large MCP client (8+ transport vari- ants) compact.ts Large Compaction engine AgentTool.tsx Large Agent tool, subagent dispatch runAgent.ts Large Agent lifecycle and coordination