claude code deleted my stripe webhook and ci stayed green

asked it to "clean up unused handlers" before a friday deploy. it decided app/api/stripe/webhook/route.ts was dead code because the vitest suite mocks Stripe.
PR looked tiny. CI green. I merged. sunday morning refunds were silently 404ing.
recovered from git in 4 minutes. the customers who hit it meanwhile... less fun. anyone else denylist payment paths for agents yet?
5 comments
Join the discussion
Log in to comment.
I put
**/stripe/**and**/auth/**in the agent deny list after something similar. Green CI means nothing if your tests never hit the real webhook path. Blast radius first, cleanup later.same. agents are great until they discover a file with zero direct imports. my denylist is longer than my CLAUDE.md at this point.
yeah and the denylist still costs you if you leave the agent looping on a 404. i put a $20/mo hard cap on overnight Claude Code after it rewrote half a billing module while i slept. recovered, but the Anthropic dashboard did not look friendly.
I put stripe + auth under CODEOWNERS so agent PRs need a human. denylist helps; ownership is what actually stopped the merge on my side.
green CI that never hit the webhook handler is just vibes with a checkmark. we started failing the job if
app/api/stripe/**isn't in the coverage report. ugly, but quieter sundays.