Claude Code Agent Loop Deep Dive (1): From Tool Declarations to Pre-Execution Approval
In the opening article , I introduced the five-line skeleton of an agent loop: call the LLM, check for tool_use , execute requested tools, and stop when there is no tool call. This article examines the first question inside every iteration: how does the LLM know which tools it can call, and what still happens after it asks to call one? More concretely: Why does an LLM know that Read exists in the…
The article delves into the inner workings of an agent loop, specifically how the LLM determines which tools it can call and what happens after requesting a tool.
A complete Messages API request contains three sections: system prompt, available tools, and conversation history. The model only calls tools listed in the tools array during training. The tools section is essentially the LLM's tool menu.
When the LLM receives a tool request, it may not execute the tool immediately. Instead, it can present an approval prompt, especially for potentially destructive actions. This is the only exception to the rule that the user is absent during most of the loop.
The loop includes mechanisms for permission approval, interruption, and iteration limits. Claude Code uses several sources of approval rules, prioritizing them based on their importance. These sources include abortController, denyRule, askRule, and defaultMode.
When no automatic rule can decide, the control flow involves presenting an approval dialog to the user. The user's deliberation time does not add API cost as the loop awaits a Promise. Three approval sources can also race together: user interface, PermissionRequest hook, and an AI classifier. The first result is authoritative and decisive.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.