207 commands + 184 tools as data structures. List capabilities without invoking them. Registry is source of truth.
Agent Primitives
from the $2.5B Leak
Anthropic's Claude Code source was accidentally exposed. Here are the 12 architecture patterns every agent builder should steal.
If your agent doesn't have at least six of these, you have a demo. Not a product.
Built-in / Plugin / Skill trust tiers. Bash tool alone has 18 security modules. Pre-approved patterns, destructive detection.
Full state as JSON: messages, tokens, permissions, config. Reconstruct any session after crash. Zero data loss.
Compaction hooks + daily promotion logic. Prevent context rot over long conversations. Memory stays sharp.
soul.md for personality. user.md for profile. memory.md for decisions. Loaded at session start. Promoted daily.
Cron-driven agent gathers context from APIs, reasons about your needs, acts before you ask. Posts alerts.
Every tool classified: Read / Mutate / Destructive. Pre-approved safe patterns. Flagging before dangerous ops.
Graceful fallback with backoff retry logic. Not crash-and-burn. Agent degrades instead of dying.
Haiku for simple, Sonnet for medium, Opus for complex. Right model for right subtask. 50-80% savings.
Session-start loads context. Pre-compact saves state. Post-build runs tests. Lifecycle automation at every edge.
Every grant/deny recorded with context. Full audit trail. Decisions replayable for debugging and compliance.
User-defined skills start at lowest trust. Never escalate silently. Permission boundaries are deliberate.