Discussion about this post

User's avatar
Atin Agarwal's avatar

What makes this worse than classic privilege creep is that the approval binds to the command's name, not its context — 'Always Allow' for curl in a scaffolding task quietly authorises exfiltration in every future task the agent runs. And it survives review because the audit trail shows a human consented; nobody logs what the human believed they were consenting to at the time. I've come to think per-task permission scoping with expiry is the only honest default, even though it reintroduces exactly the prompt fatigue that caused the click in the first place.

No posts

Ready for more?