Skip to content

Safety and Circuit Breakers

Marius Egerhei Torjusen edited this page Oct 3, 2026 · 1 revision

πŸ›‘οΈ Safety, Guardrails, and Circuit Breakers

Autonomous code loops operate with elevated local permissions. Without strict containment, a runaway loop can exhaust budgets, commit secrets, corrupt git history, or introduce subtle regressions.

Loop Engineering enforces a fail-closed, multi-layered security architecture.


1. Absolute Path Denylist

The loop must never auto-edit or stage files matching the denylist. Any attempted modification triggers an immediate halt and human escalation:

.env
.env.*
**/secrets/**
**/credentials/**
**/*_key*
**/*_secret*
.terraform/**
k8s/production/**
**/migrations/**          # unless running a dedicated, human-supervised migration loop
auth/**
payments/**
billing/**

This invariant is declared in loop-constraints.md and enforced by the checker subagent.


2. Auto-Merge Prohibition

Default Policy: Autonomous loops are forbidden from auto-merging pull requests.

When automated merges are permitted for micro-fixes, they are strictly restricted to trivial, non-operational modifications:

Permitted for Auto-Merge Strictly Forbidden from Auto-Merge
Typo corrections in documentation Core behavioral or runtime changes
Formatting and lint fixes in test files Dependency version bumps
Standardized import ordering Lockfile changes (package-lock.json, Cargo.lock)
Config in explicitly allowlisted docs/ paths Any path matching the denylist

3. Circuit Breaker Mechanisms

Circuit breakers act as mechanical fuses that interrupt execution when operational anomalies are detected:

                               LOOP EXECUTION
                                     β”‚
                 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                 β–Ό                   β–Ό                   β–Ό
           MAX STEPS EXCEEDED   BUDGET CEILING HIT   PING-PONG EDIT DETECTED
                 β”‚                   β”‚                   β”‚
                 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                     β”‚
                                     β–Ό
                       CIRCUIT BREAKER TRIPPED (KILL)
                                     β”‚
                       β€’ Revert worktree changes
                       β€’ Append failure event to loop-run-log.md
                       β€’ Post escalation alert to Slack/Linear
                       β€’ Halt process with exit code 1

1. Step Count & Timeout Breakers

  • Max Iterations: Default cap at 15–20 tool steps per run. Loops must not run open-ended loops without a hard counter.
  • Wall-clock Timeout: Enforced at 10–15 minutes max per invocation.

2. Financial & Token Ceilings

  • Per-run Budget: e.g., max $1.50 or 250,000 tokens per invocation.
  • Daily Budget: Hard monthly/daily limits configured in loop-budget.md.

3. Ping-Pong Edit Detector

If an agent modifies the same file, tests fail, and it modifies the same lines back and forth more than twice, the ping-pong breaker trips to prevent infinite regression cycles.

4. Test Degradation Trap

If the total number of passing unit tests decreases after an agent edit, the checker immediately rejects the candidate diff and reverts the worktree to the clean base.


4. Human-in-the-Loop Escalation Protocol

When a circuit breaker trips or an unresolvable conflict occurs:

  1. The loop writes a structured escalation report to STATE.md under ## ⚠️ Blockers & Escalations.
  2. A notification is dispatched via webhook or MCP to the designated human triage channel (e.g. #agent-escalations).
  3. The loop enters an idle HOLD state until a human engineer reviews and resets the ledger.