Dude, I work with these things daily. Most of the harnesses have a literal stop button. Most of the interfaces prompt you to allow or deny commands. These aren't things that are part of the LLM. They are the completely normal, deterministic code of a harness.
This really isn't that deep. The "thinking" loops it runs are just token production. You can literally read its "thoughts".
Running LLM suggestions in a loop without any input is a stupid idea.