I built a permission-first CLAUDE.md + agent stack for Claude Code (free, MIT)
I've been using Claude Code daily for months. And I kept hitting the same wall: The agent would just start doing things. No plan. No approval. Just... acting. It deleted files I didn't want deleted. It refactored things I didn't ask it to refactor. It made "helpful" assumptions that broke my archite










