A coding agent is a loop appending to a context window, and the window is what runs out. Instruction files, permissions, hooks, skills, MCP, subagents and memory explained as one mechanism, mapped across Claude Code, Codex and OpenCode.
Second of three episodes on coding agents: how Claude Code, Codex, OpenCode and pi handle context, instruction files, permissions, hooks, skills, MCP, subagents and memory. Claude Code is the running example; each section maps the same concept to the other three.
A coding agent is a short program: send the conversation to the model, run whatever tool it asks for, append the result, repeat until the model answers with text alone. Every appended file and test log stays in the window for the life of the session, so the context window, not the model, is what runs out. Every mechanism below is a way of deciding what enters the window and when. Compaction summarizes the history when the window fills; Claude Code's auto-compact window and /compact are configurable, and /compact is itself an expensive request while /clear is free. Thinking is dialed by effort level in Claude Code and by model_reasoning_effort in the Codex configuration reference.
AGENTS.md has become the cross-vendor instruction file, stewarded by the Agentic AI Foundation under the Linux Foundation and read by Codex, OpenCode, Cursor, Gemini CLI, GitHub Copilot, Jules, Aider, Zed and more. Claude Code reads only CLAUDE.md, bridged with an @AGENTS.md import; the Claude Code memory docs describe the managed, user, project and local layers, lazy subdirectory loading, @ imports up to four hops, path-scoped .claude/rules/, and re-injection after compaction. Codex's AGENTS.md guide walks from the git root down with a 32 KiB default cap; OpenCode rules read AGENTS.md with a CLAUDE.md fallback plus an instructions array in opencode.json; pi concatenates AGENTS.md from home, parents and cwd. What belongs: commands, conventions and boundaries the model cannot derive from the code, under a couple hundred lines. Instruction files are context, not enforcement.
Claude Code permissions use Tool(pattern) rules with deny over ask over allow, and the docs list how allowlists leak: absolute paths, sh -c, and unstripped wrappers like devbox run. Permission modes are default, acceptEdits, plan, the classifier-backed auto mode, and bypassPermissions. Codex separates sandbox modes (read-only, workspace-write, danger-full-access) from an approval policy. OpenCode permissions map globs to allow, ask or deny with last-match-wins. pi ships no permission system by design. Claude Code sandboxing uses Seatbelt on macOS and bubblewrap on Linux, with filesystem and network-domain allowlists. The cautionary case is PocketOS, April 2026, where a Cursor agent found an unscoped hosting token and deleted the production volume and its backups in seconds, reported by The Register and Fast Company.
A hook runs a program at a fixed point in the loop and its exit code or JSON decides what happens next; unlike an instruction, it fires every time. Claude Code hooks cover more than thirty events; exit code 2 always blocks on blockable events, PreToolUse can stop a call, Stop can refuse to end a turn, PostToolUse cannot block. Codex hooks mirror the event set and require trusting each hook definition by hash. OpenCode plugins expose tool.execute.before, permission.asked and session events; Gemini CLI hooks and Copilot CLI hooks exist too. The three worth having: a PreToolUse block on destructive commands and secret files, a post-edit formatter and typecheck that feeds errors back, and a Stop hook that holds the turn open while tests are red.
A skill is a folder with a SKILL.md whose name and description load at startup, whose body loads when a task matches, and whose bundled files load on demand. The format is the open Agent Skills standard, adopted by Codex, OpenCode, Cursor, Gemini CLI, GitHub Copilot and dozens more. Claude Code skills absorbed custom slash commands; frontmatter flags decide whether a skill is user-invoked, model-invoked or both, and side-effecting skills like deploy should be user-invoked only. A loaded skill body persists in the window, and load-time shell commands can splice live state into a procedure.
The Model Context Protocol standardizes tools, resources and prompts over JSON-RPC, via stdio or streamable HTTP with OAuth; Anthropic donated it to the Linux Foundation and the current revision adds stateless per-request negotiation, Tasks and MCP Apps extensions. Tool definitions traditionally loaded into context for every server every session. Anthropic's Code execution with MCP named the two costs and reported 150,000 tokens down to 2,000. The fix that shipped is deferred loading: Claude Code defers MCP tool definitions by default via tool search, also available at the API level; Codex MCP config offers per-server enabled_tools and disabled_tools; OpenCode MCP servers filter tools by glob with no lazy loading documented. Claude Code's cost guidance: prefer CLI tools over MCP servers, scope servers per project, disable what you have not used, and watch the 25,000-token output cap.
A subagent is a second loop with a fresh window; the parent sees only its result. Claude Code subagents are Markdown files with frontmatter for model, tools, permission mode, memory and worktree isolation, started without conversation history unless forked; agent teams add messaging between named teammates at roughly seven times the tokens of a plain session. Codex subagents are TOML files with developer instructions, model, effort and sandbox mode. OpenCode agents split into primary agents and @mention subagents, each with its own permission block. Recommended cast: a read-only scout on a cheap model, a fresh reviewer per diff, one writer per task. Claude Code worktrees create isolated checkouts with --worktree, EnterWorktree, subagent isolation: worktree, .worktreeinclude for gitignored files, and enforcement that blocks edits reaching back into the main checkout; Codex and OpenCode leave worktree management to git.
Memory is files. Claude Code auto memory is on by default: a per-repository directory shared across worktrees with a MEMORY.md index (first 200 lines loaded) and topic files read on demand, recording preferences, feedback and learned project facts. Codex memories are an opt-in local store controlled per session. OpenCode has no first-party memory beyond snapshots. Both vendors frame memory as a recall layer: rules that must always apply belong in the instruction file, prohibitions in hooks.
The Gnothi companion show on Claude Code goes from a first change in the terminal to a repeatable delivery workflow: OCDevel Claude Code Podcast.