Claude Code users approve 93% of permission prompts, raising agent security concerns
annetgriffin · x · 2026-09-23
hnshah points out that Claude Code users approve about 93% of permission prompts, making the "Allow" button look a lot like "Continue" — what Anthropic calls approval fatigue.
He has been auditing permission settings across ChatGPT, Claude, Grok Bot, Muse and other agents, flagging notable details:
- Grok Bot's docs say every Bot on one account shares the same cloud computer
- Replit separated dev and production databases only after its Agent deleted production data
He is hosting an AI Permissions 101 session on how to review what an agent can reach, which actions still deserve manual approval, when read-only access suffices, and when a hard system boundary is worth adding.
More from coding & agent
- Distill Lock: context as a build artifact with byte-identical, drift-proof, offline-verifiable output — _akpiper · 2026-09-23
- Open-source Agentic Engineering Guide: 10 parts, 33 chapters on shipping AI agents to production — _akpiper · 2026-09-23
- Learning to code still matters: Motivation + Knowledge + Skills + AI beats Motivation + AI — iamKierraD · 2026-09-23
- Low-VRAM user claims applying a Qwen-style chat template fixes Ternary Bonsai 2's tool calling — needthosepylons · 2026-09-23
- pi-voice: Handy creator ships a voice extension for Earendil Pi — mitsuhiko · 2026-09-23
- Practical guide: using Gemini API skills with your coding agents — patloeber · 2026-09-23