1 Comment
User's avatar
Atin Agarwal's avatar

What makes this worse than classic privilege creep is that the approval binds to the command's name, not its context — 'Always Allow' for curl in a scaffolding task quietly authorises exfiltration in every future task the agent runs. And it survives review because the audit trail shows a human consented; nobody logs what the human believed they were consenting to at the time. I've come to think per-task permission scoping with expiry is the only honest default, even though it reintroduces exactly the prompt fatigue that caused the click in the first place.