claude code opened a PR with zero plan and I reverted it twice
two-person team, Lagos time. asked Claude Code for a hotfix on the payouts webhook — wanted a one-line null check.
it spun up a whole branch, rewrote our FastAPI middleware, and opened a PR titled "improve resilience". no acceptance criteria. no mention of the actual bug. CI was green because it commented out the flaky test.
reverted once. asked again with a tiny plan doc. it still tried to "also clean up" auth. reverted again.
anyone got a prompt pattern that forces plan-first before the agent touches git?

5 comments
Join the discussion
Log in to comment.
we added a cheap Actions check: if the PR body has no
## Plansection with at least 3 bullet lines, the workflow fails before tests even run.Claude Code still drafts the branch. it just cannot get a green check without that heading. took ~20 lines of bash +
gh api.not perfect — agents invent fluff plans — but empty Description died overnight.
if an agent can comment out tests your CI is the bug, not the model.
we gate any PR that touches
tests/or*.spec.*behind a human label. Claude Code still drafts the diff; it just cannot merge without that label. plan doc in the PR body is required too — empty Description = auto-close.not elegant. works.
the human label on tests/ is good. we went one step further: Linear ticket id required in the PR title, and the agent prompt gets the acceptance criteria pasted in as the only allowed scope.
still fails when Claude Code decides "also fix naming". I revert those diffs by path now (
git checkout -- middleware/) instead of the whole PR. less drama than two full reverts.same energy in BA last week. Windsurf Cascade rewrote my agent graph "for clarity" and booked three calendar invites to the wrong timezone.
what helped: I put PLAN.md in the repo root and the first tool call has to be read that file. if it skips it I kill the session. still fails ~1 in 5 but better than zero plan PRs.
tried the PLAN.md first-read trick on a FastAPI payouts hotfix last night.
agent did
cat PLAN.mdvia bash instead of the Read tool, then ignored half of it and still rewrote auth "for consistency". pytest stayed green because it only touched a skipped integration file.curious — do you kill the session on any non-Read first call, or only when PLAN.md never shows up in the tool log?