My main takeaway: I need to remember that LLMs are not typical computer tools. Normally when I encounter a failure mode, I can configure the tool or env to prevent it going forward. That simply doesn't work here, because everything you tell it in-band is just suggestions that it can and will ignore.