Lesson 3.2 ended with a promise: an audit. Here it is. Three risks, and not one of them is a bug in the loop.
Every failure in last lesson's table was something the loop did. These three are things you do while it runs. That is why there is no hook for any of them, and why this is the one list nobody else is going to run for you.
The audit: three risks a working loop creates
The names aren't mine. They, and the "stay the engineer" framing this lesson is titled for, come from Addy Osmani's and IBM's loop-engineering write-ups. What this lesson adds is a question for each one that you can go and check.
| Risk | The question | Where the answer lives |
|---|---|---|
| Comprehension debt | Can you explain why the last three merged fixes worked, without re-reading the diff? | In your checker's evidence report, if you kept one. |
| Intent debt | Does a skill entry capture this decision, or does the next run derive it again from scratch? | In the skill file. Open it and read its last edit. |
| Cognitive surrender | Of the last five runs, how many did you actually read before approving? | In the pull requests you merged. Count them. |
Comprehension debt. If you can't explain the last three fixes, you are reviewing code you don't understand. It is last lesson's "done"-but-broken row, asked of a person instead of a loop.
Intent debt. Intent that only lives in a transcript is gone once the session ends. A skill is only as true as its last edit, and nothing checks that.
Cognitive surrender. This one is exactly countable, and no mechanism catches it. Counting is the mechanism. Go and count; the number you remember is always higher than the real one.
All three are answered by looking, not by remembering. The diff, the skill file and the merge history are all on disk. That is the whole audit.
The audit, run on this course's loop
Run it on the loop you built, not a hypothetical one. Here are the honest
answers for the loop from Modules 1 to 3, on the fix/apply-discount branch.
| Risk | This loop, honestly | What to do about it |
|---|---|---|
| Comprehension debt | The evidence exists, and nothing keeps it. The checker reports the command, its exit code and the last line of output. Then the window closes and the report is gone. | Put the report in the pull request body, beside the failing test the connector already names there. |
| Intent debt | The skill holds the how. Nothing holds the why. The prose stop condition explained one run and expired with the session that read it. | When a fix surprises you, that is a skill entry, not a commit message. |
| Cognitive surrender | No data. Every run so far has been watched, and nothing has merged while you were asleep. | Start the count the first time it runs on a schedule. |
No data is not a pass. It is a question nobody has opened yet.
The adoption ladder
Five rungs, climbed one at a time and never skipped. Skipping is how you end up with a loop you can't account for.
| Rung | Name | What it means |
|---|---|---|
| 1 | Manual | You type it and you watch it. Every turn happens in front of you. |
| 2 | Triage | It runs on its own and reports, real failure or flaky. It changes nothing. |
| 3 | Draft | It opens the pull request. An open pull request is not a reviewed one, as Module 2 said. |
| 4 | Verified PR | A checker that isn't the maker produces the evidence first. You read the evidence, then the diff. |
| 5 | Auto-merge | Green means merged, and nobody reads anything. |
Rung five means letting the loop call mcp__github__merge_pull_request, and
that is the one tool your own hook already refuses.
Where this loop honestly sits
Rung three, draft. That holds even though rung four's checker is already built.
You might think: I built the checker, so why not four? Because rung four is a claim about your reading, not the checker's. Having a checker doesn't mean you read what it produced.
So what buys rung four? The price, for this loop:
- Twenty runs where the checker's evidence and your own reading agreed. The number is mine. The counting isn't.
- The evidence kept, in the pull request, not in a context window that has already closed.
- The static-check box stops coming back empty. A repo with no linter has one fewer independent signal for a checker to produce.
And the rule underneath it, for any loop:
The rung you're on is the one you have evidence for, not the one the tooling can reach.
Rung five I have never given to anything on a repo someone pays for. That is a judgment, not a rule, and you are allowed to disagree. You should just have to argue for it, out loud, to someone.
After this lesson
You will be able to:
- name the three risks a working loop creates in the person running it: comprehension debt, intent debt and cognitive surrender;
- check each one by looking at something on disk, not by remembering;
- run the audit against your own loop and say what to do about each answer, including "no data";
- place that loop on the five-rung adoption ladder, and name what it would take to earn the next rung.
What comes next
In Lesson 4.1: three more loops that reuse every piece of this one (a test-stabilizer, a housekeeper and a UI scoring loop) and the rung each of them honestly starts on.
Companion article
Every hook, script, and command in this course, written up and executed: How to build an agent loop in Claude Code