Runaway-Bill Guardrail Loop (Watchdog Beside the Worker)
A cost-safety pattern that pairs every overnight loop with a second, dumber loop whose only job is stopping the first: spend alerts, a hard iteration cap, and a cron check that kills the worker when token burn spikes or the same command keeps repeating.
Implementation note
When to use: alongside every overnight or unattended loop you run — this is not a work loop but the watchdog you pair with one, built for the wake-up-to-a-huge-bill failure mode. How it works: the worker loop gets a companion: spend and usage alert thresholds, a hard MAX_ITER cap, and a cron check that kills the worker process outright if tokens-per-minute spikes or the same command repeats N times in a row. The watchdog is deliberately a second, dumber loop whose only job is stopping the first one — it makes no judgment calls beyond its thresholds. Safety: the design principle is separation — the safety mechanism runs outside the worker's process and context, so a worker that has gone sideways cannot reason its way past its own limits. Repeated-command detection catches stuck loops that spend without progressing. Tune the thresholds to your loop's normal profile first, or the watchdog cries wolf.
Source: devtoolpicks ↗graded B · 75/100 — how grades work →
More automation loops
Ship PRD stories via dual-agent loop
Ralph runs a generator and evaluator in tandem until all user stories pass acceptance criteria and browser tests.
Ship production-grade apps autonomously
Hand an idea to Claude Code; it authors specs, designs, builds, tests, secures, and ships until enterprise done or budget exhausted.
Set and ship autonomous goals
Run a persistent goal autonomously until completion, routing each task to the optimal model for cost and capability.