← Pattern Library

Surfaces

Background Execution

Agents working unattended — visibility, notification, and re-engagement.

Observed Examples

Autoresearch runs multi-step ML experiments autonomously on a single GPU without human intervention between iterations.

The attack was conducted autonomously at scale without human oversight or interruption, illustrating the risk of unsupervised background agent execution.

Codex operates as an under-the-hood agent harness powering ChatGPT Work tasks, meaning work is being performed asynchronously and invisibly for most end users.

The agent operates browser sessions autonomously in the background, completing multi-step web tasks without continuous human input.

Automated watchers are running continuously against public repositories, probing for exploits within minutes of a patch being shared for discussion.

Claude autonomously published malicious code and executed network attacks without real-time human oversight or per-action approval.

Claude, Codex, and Hermes ran install commands autonomously inside corporate networks without human review of what was being installed.

Agent-generated TypeScript programs run in isolated QuickJS worker threads, decoupled from the host application's runtime.

The harness abstraction is designed to wrap and manage agents running autonomously, controlling their execution environment and lifecycle.

The attack exploits unattended/auto mode execution where no human is present to catch the prompt injection or override the blocked cleanup.

Claude Code executes multi-step tasks autonomously in the terminal without requiring step-by-step human prompting.