Claude Code ships a conditional instruction system: the root CLAUDE.md loads at session start, while nested per-directory CLAUDE.md files and path-scoped .claude/rules/ entries load only on demand β docs quoted in the supplied sources say they load 'on access', when Claude reads files in that part of the repo. Redditor microlatency reports a failure mode where that access trigger fires only for the native Read tool and not shell access: when Auto Mode steers the model toward cat/sed via Bash, scoped repository instructions are silently never injected; two further independent accounts (gabgoss's GitHub issues #90449/#90450, and mudmohammad's transcript token accounting finding CLAUDE.md/agent configs unloaded in 9/10 sessions) support instruction absence in routine work, though none of the supplied web material isolates the Read-vs-shell mechanism and no Anthropic acknowledgment of the specific bypass appears anywhere supplied. The snippets do corroborate the documented on-demand loading design and a long history of nested-loading bugs (anthropics/claude-code issue #2571), and a related confirmed defect β the v2.1.277 AGENTS.md fallback silently gated on telemetry being enabled, acknowledged by Anthropic and fixed in v2.1.281 per the case record β shows conditional instruction delivery breaking is a real pattern for this harness.
Independently converges with Manners-vs-Physics and Guardrail Illusion: Claude Code's on-access instruction loading is a probability barrier keyed to the model's tool choice, and mudmohammad's 9/10-session measurement shows it silently failing in real work β dated third-party receipts for the deterministic-boundary position he already argues. It bears directly on his own stack rather than merely illustrating it: the router project's markdown-defined Claude Code agents depend on nested CLAUDE.md delivery, so the indicated Read-vs-shell regression test and deny-permissions on cat/sed are immediate build actions, and the failure mode sharpens his context-engineering claim that just-in-time loading needs a deterministic trigger (hooks/path-level injection) instead of model cooperation.
ip:concept.manners-vs-physicsip:concept.guardrail-illusionip:framework.context-engineeringip:concept.claude-md-patterndev:project.routerdev:technology.claude-coderadar:concept.claude-coderadar:claude-code-agents-md-supportradar:claude-code-machine-level-config-bleedradar:claude-code-denied-read-secret-bypassradar:graft-automatic-agent-contextradar:concept.deterministic-guardrails
queries asked of Scott's wikis
- deterministic control plane agent behavior vs prompt adherence
- nested CLAUDE.md scoped instruction loading deployments
- router project markdown-defined Claude Code agents
- agent memory wiki on-demand loading context injection
- tool call gating deny permissions shell commands
- agent harness regression testing transcript audit
2026-10-07T09:24:55Z
bestpromptfinder's post adds a second, documented (not defective) mechanism of the same failure class β AGENTS.md silently skipped whenever a CLAUDE.md exists β widening the case's meaning from one bypass bug toward 'conditional instruction delivery is fragile in Claude Code as a class,' while the specific Read-vs-shell hypothesis gains no new evidence and its open questions (post-v2.1.281 behavior, Auto Mode causality, subagent loading) stand. Heat drops to low: the magnitude-valve flag is a stale mid-September spread reading, and current numbers are dead (0.0 pts/h, 12.5th percentile, newest items at score 0 with falling ratios) β thin additions, not an expanding periphery.
2026-10-07T09:23:21Z
evidence attached: reddit.post.1wzrlsr β Second, distinct mechanism (documented AGENTS.md-vs-CLAUDE.md precedence) of repo conventions silently not reaching the coding agent β same failure class the case is re-judging.
2026-10-04T05:32:44Z
grounded: converges/high β Independently converges with Manners-vs-Physics and Guardrail Illusion: Claude Code's on-access instruction loading is a probability barrier keyed to the model'
2026-10-04T05:24:41Z
A third independent account (mudmohammad's transcript token accounting: CLAUDE.md/agent configs unloaded in 9/10 real sessions) shifts the case's meaning from 'mechanism plausibly bypassed' toward 'instruction absence measured in routine work' β though it records the symptom, not the native-Read-vs-shell cause. The September attention episode is fully spent (peak 133 pts/h vs 0.17 now, 37th percentile, newest item score 1), so the magnitude-valve spread is a mid-September reading, not a current one; heat drops to low while the open question reduces to whether scoped loading persists post-v2.1.281.
2026-10-04T05:23:32Z
evidence attached: reddit.post.1wx7c7u β Measured transcript accounting finds CLAUDE.md and agent configs unloaded in 9/10 sessions plus quantified context-bloat and subagent model-inheritance waste β practical evidence that repo instructions go absent in real coding work.
2026-09-23T23:15:40Z
magnitude valve eligible (multi-platform, top-decile engagement) and never alerted; deterministic escalation to deliver
2026-09-23T12:21:55Z
evidence attached: hn.story.49814947 β This may materially contextualize when Claude Code loads repository instructions, though the telemetry claim is unverified.
2026-09-21T14:23:42Z
relevance=high case never alerted; deterministic escalation to deliver
2026-09-20T19:22:38Z
evidence attached: hn.story.49778253 β The report directly bears on Claude Code's instruction-file discovery and fallback behavior.
2026-09-20T12:25:51Z
The latest attachment is another headline about AGENTS.md compatibility, not evidence that scoped instructions load reliably through shell access or that the reported bypass is fixed. The broad-spread reading and dominant compatibility discussion sustain high attention, but the defect hypothesis has not gained independent verification.
2026-09-20T12:21:56Z
evidence attached: hn.story.49774919 β shared external link with case evidence
2026-09-19T22:23:07Z
The new settings.json precedence allegation does not distinguish configuration behavior from instruction discovery and supplies no reproduction, so it neither corroborates nor explains the reported shell-access bypass. Discussion is largely repetitive, but the supplied broad-spread reading and dominant compatibility thread sustain high attention without advancing the defect hypothesis.
2026-09-19T12:23:50Z
The newly attached headline repeats AGENTS.md compatibility coverage without clarifying scoped instruction delivery or establishing a fix. Broad attention to repository-instruction compatibility still warrants high heat, but it does not independently corroborate the native-Read-versus-shell loading gap.
2026-09-19T12:21:38Z
evidence attached: hn.story.49765635 β Claude Codeβs AGENTS.md support materially clarifies its repository instruction-loading behavior.
2026-09-19T08:26:33Z
Repository-instruction compatibility has become a front-page attention event, with the spread reading warranting high heat despite no new substantive evidence. That attention concerns AGENTS.md fallback, not independent confirmation or repair of the native-Read-versus-shell loading gap; the defect hypothesis remains unverified.
2026-09-19T05:28:25Z
A commenter now quotes a specific changelog entry, strengthening the AGENTS.md fallback claim beyond headlines, but filename compatibility remains distinct from tool-triggered scoped instruction loading. Neither the quoted release nor its platform exclusions establishes a reproduction or fix of the reported bypass.
2026-09-18T21:22:45Z
The newest headline claims conditional AGENTS.md fallback, but the supplied evidence contains no Anthropic changelog despite the attachment rationale invoking one. Filename compatibility still does not establish whether shell access triggers scoped instructions, so this adds neither independent confirmation of the reported defect nor evidence of a fix.
2026-09-18T21:22:01Z
evidence attached: hn.story.49760187 β Anthropic's changelog provides first-party corroboration that Claude Code now falls back to AGENTS.md, materially changing repository instruction discovery.
2026-09-18T21:08:14Z
The additional AGENTS.md headline supplies a claimed release version, but no evidence about scoped instruction-loading behavior; compatibility support is not evidence that shell access now triggers instruction injection. This remains an unconfirmed reliability concern worth a targeted regression test, rather than a corroborated defect or demonstrated fix.
2026-09-18T20:22:41Z
evidence attached: hn.story.49759414 β Claude Code's new AGENTS.md support materially clarifies and broadens the case about repository instruction discovery and loading.
2026-09-18T19:57:21Z
The attached AGENTS.md-support headline concerns instruction-file compatibility, not whether shell access triggers scoped instruction loading; it neither corroborates nor resolves the reported failure. The concrete audit warrants watching, but related coverage and anecdotal workarounds do not establish an independent reproduction or an upstream fix.
2026-09-18T19:22:26Z
evidence attached: hn.story.49758250 β Claude Code adding AGENTS.md support materially bears on repository instruction discovery and cross-harness configuration behavior.
2026-09-17T22:36:22Z
grounded: converges/high β The reported tool-dependent instruction loading converges with Scottβs deterministic-agent-control-plane position and exposes a concrete reliability risk for hi
2026-09-17T22:31:52Z
origin walked (codex/luna, conf 0.99): anchor reddit.post.1wj7v4y -> echo.github.5f0525dbf6 by Gabriel Gosselin (gabgoss)
2026-09-17T22:30:32Z
case created β The reported audit of 480 main sessions and approximately 1,200 subagent transcripts identifies a concrete harness failure mode, although the excerpt does not establish permission-mode causality.