For me the problems with agent permission prompts are twofold: 1) I generally have a lot of things where I am okay with the agent calling a specific tool (maybe in certain ways) as much as it wants. This allowlisting approach is often defeated by the model's own proclivity to get fancy with inline scripting. 2) Checking for intent/alignment of the agent is the primary reason I still even use permission prompts, becau…
See also: https://gtfobins.org/
> GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.