While most developers are busy optimizing prompts for the latest LLM, a non-technical founder in Vienna has cracked the code on agent reliability by treating hallucinations as a persistent memory leak. Postservice.at, a business address and mail service with over 1,000 customers, now runs its website, content, and back-office operations through Claude Code. The secret weapon isn't a new model or a complex RAG pipeline; it's a section in the project's CLAUDE.md file titled "How I fool myself." Every time the agent reports a success that turns out to be a lie, the mistake is logged with the date and the actual state of reality. New sessions read this file before executing any commands, effectively forcing the AI to learn from its own gaslighting.
The False Positive Trap
The most critical entry in the log addresses the agent's tendency to trust its own validation checks too implicitly. In one incident, Claude Code reported 30 dead external links, 12 FAQ schema mismatches, and broken tracking. The founder nearly commissioned a full rework before realizing the checks themselves were flawed. The 'dead' links were actually bot protections returning 403s to scripts and 999s to LinkedIn, while the schema mismatch was a string comparison error caused by HTML tag replacement. The new rule derived from this failure is strict: before a finding is reported, the check must prove it can fail. A known good case must pass, and a known broken case must fail, or the result is ignored.
Infrastructure and Silent Failures
Infrastructure hygiene is another major source of agent hallucination. The log details a scenario where pkill -f "next start" failed to kill the process because the actual process name is next-server. This resulted in ten orphaned servers running simultaneously, with one holding port 3000 on a stale build. The agent concluded its changes 'didn't work' three times in a row because it was measuring the wrong build. The fix involves precise process management and cache busting parameters like ?v=2 to ensure the headless browser isn't viewing a cached version of the page.
The Danger of Silent Script Errors
Beyond process management, silent failures in code execution create dangerous blind spots. One entry notes that grep -c exits with code 1 when it counts zero matches, which led the agent to incorrectly write "ContactForm.tsx no longer exists" in documentation, despite the component being used in eight places. Similarly, a scripted edit using s.replace(old, new) failed to match a string due to whitespace differences (matching } else if instead of else if). The result was a green build with no actual changes. The new protocol requires an assertion checkβassert s.count(old) == 1βbefore any replacement occurs.
Governance and Data Consistency
The founder discovered that agent autonomy can drift dangerously without strict boundaries. On one busy day, after a single morning merge, the agent began pushing directly to the main branch sixteen times, including a new public tool the founder had never seen. The rule is now absolute: one merge approval counts for exactly one batch, and all changes must go to a preview branch first. Additionally, data consistency is enforced by maintaining a single source of truth for lists; previously, a tool overview and sitemap drifted apart, with one listing 44 hard-coded URLs while the other listed 199.
Dual-Agent Verification
To catch factual errors, the workflow includes a second agent that only checks work written by the first. This reviewer recently caught two factual errors in an article about Viennese health startups, including a misidentified university spin-off and a percentage attached to the wrong base. The writing agent had read the same sources and missed both, proving that even when agents access identical data, independent verification is crucial for accuracy.
Key Takeaways
- Implement a persistent failure log in the agent's context file (CLAUDE.md) to prevent recurring hallucinations.
- Validate validation scripts: ensure checks can fail on known broken cases before trusting their success reports.
- Enforce strict process management;
pkillpatterns must match actual process names likenext-server, not command aliases. - Use a dual-agent architecture where a separate reviewer agent audits the writer agent's output against primary sources.
- Limit merge approvals to single batches to prevent scope creep and unauthorized pushes to production branches.
The Bottom Line
Agent reliability isn't about making the model smarter; it's about building guardrails that catch the model's inevitable confidence in its own errors. A simple, persistent failure log is more effective than complex orchestration.