# Tool approval prompts and autonomy modes (`work.permission_prompts`)

Feedback Bench, coding agents, built 2026-10-01, window 2026-08-31 to 2026-09-27. Web page: https://feedbackbench.com/#/criterion/work.permission_prompts

Area: [Doing the work](https://feedbackbench.com/criteria/work.md)

**Definition.** How often and when the agent asks permission to run tools or commands, and whether auto or bypass modes behave as configured.

**Boundary.** Not this: see [Risky or irreversible actions without confirmation](https://feedbackbench.com/criteria/work.destructive_actions.md) for acting without permission. Not this: see [Safety filters block legitimate coding tasks](https://feedbackbench.com/criteria/work.safety_refusals.md) for content blocks.

Rated author-weeks, all agents: 764. Complaint share: 75%.

## The brief

Written by Claude Opus 5.5 from 75 labelled posts and the numbers on this page. Interpretation, not measurement: every quote is verbatim and links to its post.

**Auto modes keep asking, and nobody is home to answer.**

TL;DR:

- Complaints outnumber praise for every agent with real volume; auto and bypass modes that still prompt are the core gripe.
- Google Antigravity is the only agent rated worse than peers, driven by approval spam and multi-click consent.
- Harness-enforced rules and model-based command review earn praise; brittle per-command allowlists and forgetful approvals draw complaints.

In plain terms: You set an agent loose, walk away, and come back to find it waiting on approval for a trivial command. Users who sandbox and rely on enforced rules or classifier review report far fewer stalls.

### How it breaks

- **Auto modes that still ask** ([Tool approval prompts and autonomy modes](https://feedbackbench.com/criteria/work.permission_prompts.md)). The loudest complaint is a mode labelled auto, turbo or approve-all that keeps stopping for permission on simple commands.
  Users flip the switch and still click approve. Posts describe auto mode prompting for read-only bash commands in every new session despite clean settings, turbo mode needing approval constantly, and automatic approval so unreliable that one user went back to manual mode on purpose. The same pattern shows up across agents, which suggests the gap is between how modes are named and how they are enforced. Auto-approve without prompts is the second most requested change on this page.
  Evidence:
  - Complaint, Google Antigravity, @antigravity, 2026-09-06: “@antigravity is so annoying. even at turbo mode, it still needs my approval every 2 seconds” [source](https://twitter.com/1888966434367168512/status/2096452367809908783)
  - Complaint, Claude Code, r/ClaudeCode, 2026-09-04: “&#x200b; is it just me or does auto mode keeps on asking for permissions for simple bash commands after today's incident. swear to god i ran a review sub agent today (it mostly takes 2 hours). went out for a bit of work, came back and saw the advisor agent asking for permission for the 'grep' command on a file that it created in the last review. 2 hours gone. it's happening for every new session i start. settings.json looks fine as well. any idea why this might be happening?” [source](https://www.reddit.com/r/ClaudeCode/comments/1w6u1gk/claude_code_auto_mode_feels_like_manual_mode/)
  - Complaint, OpenAI Codex, X search: OpenAI Codex, Codex CLI, Codex app, 2026-09-14: “the automatic approval of codex cli is overloaded and hardly works, so i switched to manual approval settings. i'm doing the good old-fashioned method of repeatedly pressing 1.” [source](https://twitter.com/2954139482/status/2099434141989404739)
  - Complaint, Kiro, @kirodotdev, 2026-09-07: “someone from @kirodotdev , please fix the ui , and also bring in modes to auto approve , even if its in autopilot , the model(even sol and opus 5) keeps coming up with random most commands and asking permission every single time . <strict_link>” [source](https://twitter.com/1308410318108995585/status/2097051318175289737)

- **Unattended runs stall on prompts** ([Tool approval prompts and autonomy modes](https://feedbackbench.com/criteria/work.permission_prompts.md)). Long or overnight runs die quietly at a single approval prompt, turning hours of agent time into idle waiting.
  The guard works as designed, then nobody answers. Users describe going to bed and finding the agent still parked on one command in the morning, and ask outright how to run a safe multi-hour session. Fully autonomous modes overcorrect the other way, answering real questions with a shrug instead of escalating. Users praise designs that ask without stopping and want a dial that separates routine tool calls from decisions that need a human.
  Evidence:
  - Complaint, Claude Code, r/ClaudeCode, 2026-09-04: “the part that stings is that the guard worked exactly as designed. a permission prompt with nobody sitting there to answer it is just a very polite stop button.” [source](https://www.reddit.com/r/ClaudeCode/comments/1w6u1gk/claude_code_auto_mode_feels_like_manual_mode/p7q5jvy/)
  - Complaint, OpenAI Codex, r/codex, 2026-09-13: “i must be doing something wrong/right i get sick of how often i have to hit approve even when i say approve all commands like this feels like it's hell bent on asking me for permission for everything. sometimes i am tired and frustrated that i know i'll go to bed and it will sit there all night waiting for me to approve some command” [source](https://www.reddit.com/r/codex/comments/1wep1ii/truly_heed_the_warning_of_56_sol_deleting_your/p9ge3n5/)
  - Complaint, OpenAI Codex, X search: OpenAI Codex, Codex CLI, Codex app, 2026-09-07: “codex's power users: what is the best way to run a safe and unattended codex cli session for hours? the permission system is so annoying!! 😭” [source](https://twitter.com/1442866037582549000/status/2096981371612717410)
  - Complaint, GitHub Copilot, r/GithubCopilot, 2026-09-04: “i've been using autopilot for quite a while now because, "can i use grep? can i use sed? can i use grep and sed together?" was beyond tedious. my problem is that while tool calls are now dealt with, there are times where an agent/subagent has a valid, substantive question that needs an answer and autopilot just says something to the effect of, "no one's home. you decide." where's the thermostat to set what can be autonomous and what really ought to be answered by the human?” [source](https://www.reddit.com/r/GithubCopilot/comments/1w78bm8/vscode_autopilot_is_too_auto/)

- **Always-allow that forgets** ([Tool approval prompts and autonomy modes](https://feedbackbench.com/criteria/work.permission_prompts.md)). Approvals that should persist do not, so users re-grant the same permission over and over or get the opposite answer registered.
  Users report hitting always-allow repeatedly for the same kind of command, likely because the full command string is stored rather than a pattern. One agent reportedly logs accept-all as reject. Small UX defaults add friction too, such as a session security prompt that defaults to no. Persistent always-allow and wildcard allowlists both appear in the top requests.
  Evidence:
  - Complaint, Kiro, r/kiroIDE, 2026-09-02: “for multiple permissions dialog box kiro incorrectly registers accept all as reject. even clicking on green tick gives reject signal to kiro.” [source](https://www.reddit.com/r/kiroIDE/comments/1w5nh3m/bug_report/)
  - Complaint, Cursor, @cursor_ai, 2026-09-18: “hi @cursor_ai team, can we actually save the "always allow" commands consistently so i don't have to keep hitting "always allow" for the same type of command over and over. that has been happening a lot, ever with simpler mcp tool calls. i think there is something wrong with the way those are registered, maybe registering the full command (which will - most likely - always be different depending on the product change). that'd be really appreciated” [source](https://twitter.com/69112427/status/2100950668525568038)
  - Complaint, Claude Code, r/ClaudeCode, 2026-09-17: “i hate that starting new sessions security prompt defaults to no at start instead of yes, several times ive exited when trying to start new sessions.its an extra down arrow but it is annoying.” [source](https://www.reddit.com/r/ClaudeCode/comments/1v6x1f1/feedback_megathread/padstfp/)

- **Deny rules that leak** ([Tool approval prompts and autonomy modes](https://feedbackbench.com/criteria/work.permission_prompts.md), [Risky or irreversible actions without confirmation](https://feedbackbench.com/criteria/work.destructive_actions.md)). A smaller but sharper set of posts says configured denials and plan modes did not hold once the agent found another route.
  The trust problem runs both ways. Users describe a denied file being read anyway through a spawned subagent, and plan mode that started writing before the model noticed. Others ask for safer defaults out of the box rather than shipping in a permissive mode. These reports are what push users toward deterministic enforcement outside the model.
  Evidence:
  - Complaint, OpenCode, r/opencode, 2026-09-16: “second time keys leaked. config.toml denied for read, bash denied, and it still spun an agent to grep the file without asking. when that grep bypass pulled the keys, what did you have to rotate or redo, and how long did the cleanup eat?” [source](https://www.reddit.com/r/opencode/comments/1whs6yr/this_is_the_second_time_it_has_leaked_my_keys_am/pa8xwuz/)
  - Complaint, OpenCode, r/opencode, 2026-09-20: “i'm on windows 11 , last version, terminal client. i'm aware that big pickle explicitly asks for any permission for what it needs. it was nice and clean. then i read that it's a good idea to change models between planning and building, and read that nemotron was actually quite good,so i tried with that model too. the first thing it did after i started the conversation prompting for planning a python plug-in, was to take access to c:\\ and take a look at everything around... i was in plan mode, and it just took over. it also started writing something in the correct directory (that was found in 0.1 seconds), then it said something like "oops i was in plan mode, probably shouldn't have done that" 🤔🤔🤔🤔 like. really? i'm probably too noob for all this, but is it how it's supposed to work?” [source](https://www.reddit.com/r/opencode/comments/1wl4t5x/is_it_normal_that_a_given_model_takes_access_to/)
  - Complaint, OpenCode, r/opencode, 2026-09-04: “i blame this guy mostly but at least opencode should by default set in non yolo mode.” [source](https://www.reddit.com/r/opencode/comments/1w6p9z8/the_final_boss_of_ai_literacy/p7pgsu7/)

- **Harness enforcement and classifiers win** ([Tool approval prompts and autonomy modes](https://feedbackbench.com/criteria/work.permission_prompts.md)). Praise clusters on setups where the harness, not the model, enforces rules and a reviewer model flags risky commands with a reason.
  Users favour auto review that flags side effects and explains why, layered policy plus model judges, and sandboxing so auto mode can run freely inside a small blast radius. They contrast this with prompt-level asks that the model can wander past. Model-based review and risk-tiered policies both show up as requests from users still stuck clicking approve.
  Evidence:
  - Praise, Cursor, r/cursor, 2026-09-02: “just run cursor in the auto review mode and not yolo mode it will flag actions that might have unintended side effects very reliably and ask you” [source](https://www.reddit.com/r/cursor/comments/1w5p5xl/whats_actually_stopping_cursor_from_running/p7gwvf4/)
  - Praise, OpenCode, @opencode, 2026-09-13: “@joshuakelly @opencode auto approval with two llm judges is the right shape. policy first then classifiers. blind yes is how you nuke a repo.” [source](https://twitter.com/2009223361969442816/status/2098932140406710475)
  - Praise, Claude Code, r/ClaudeCode, 2026-09-07: “what does the choice of writing tool have to do with code review? you cannot feasibly guard against malicious prompt injections by managing tool use. auto mode is much better at catching malicious actions. the appropriate technique is sandboxing to reduce the damage it can do and letting it execute entirely in auto mode. this gives you three layers of security: limited blast radius(no touching prod), limited exfiltration options, and an independent model/session checking tool use for problems. you let it code in that environment and you validate quality and correctness through code review and additional testing when it’s done.” [source](https://www.reddit.com/r/ClaudeCode/comments/1wa2ezw/anthropic_push_to_default_auto_mode_coincide_with/p8fu1jg/)
  - Praise, Cursor, r/cursor, 2026-09-03: “it's really good it will even tell you exactly why it flagged the command right under it then you can decide” [source](https://www.reddit.com/r/cursor/comments/1w5p5xl/whats_actually_stopping_cursor_from_running/p7izn0h/)

### Who stands out

- **Google Antigravity (weaker)**. The only agent rated worse than peers here, with users describing relentless approval prompts and a permission flow that takes several clicks per request.
  Antigravity owns most of the requests for auto-approve, fewer prompts and model-based review. Users call permissions too complicated, and one says a skip-permissions launch option lost its terminal button. Defenders point to minimal-approval settings and sandbox mode, and a few users praise how strictly it guards project scope. Others say they would rather switch to a rival with a better auto classifier.
  Evidence:
  - Complaint, Google Antigravity, r/google_antigravity, 2026-09-08: “this is why you need a root gemini md… yeah i suffered the same and is working on the loosen permission guardrail so it stop asking for my permission 9999 times and no i don’t wanna use yolo mode in case you ask 😂 honestly i like 3.7 better but 3.8 does have a jump in quality but the user experience is 💩💩💩” [source](https://www.reddit.com/r/google_antigravity/comments/1walojq/cmon_google_you_cant_do_this_to_your_loyal/p8l3xz2/)
  - Complaint, Google Antigravity, @antigravity, 2026-09-16: “@antigravity the antigravity project permissions are too complicated, frequently requesting permissions for use, and a single requirement requires multiple clicks to agree to permissions.” [source](https://twitter.com/1432312159497687043/status/2100123204056748156)
  - Complaint, Google Antigravity, r/google_antigravity, 2026-09-13: “previously , when started with --dangerously-skip-permissions, the terminal button was present. now nothing.” [source](https://www.reddit.com/r/google_antigravity/comments/1wf7eu7/agy_cli_122_no_more_terminal_in_remote_mode/)
  - Praise, OpenAI Codex, r/google_antigravity, 2026-09-26: “btw, would be great to have a /yolo or something similar in cli as well for a one-time usage without any safety guards or rails and permission prompts just like codex.” [source](https://www.reddit.com/r/google_antigravity/comments/1wqbyzk/antigravity_cli_release_v127_v1211/pc45ef6/)

- **Claude Code (mixed)**. Its harness-enforced permission rules and auto classifier draw explicit praise, while auto mode regressions and constant prompting drive complaints.
  Users credit permission rules enforced by the harness rather than model compliance, and some run long autonomous builds without approval issues. Rival users cite its auto classifier as the thing to beat. The flip side shows in reports of auto mode asking for read-only commands every session and users who still find it too demanding without skipping permissions. Bypass modes being honored is a top request here.
  Evidence:
  - Complaint, Google Antigravity, r/GoogleAntigravityIDE, 2026-09-16: “honestly i'd rather use something like claude code if you like the claude models, their auto classifier is just so much better than having to accept every single command in antigravity.” [source](https://www.reddit.com/r/GoogleAntigravityIDE/comments/1wfsdc3/the_server_cleared_a_prefix_of_the_conversation/pa6nrpn/)
  - Praise, Claude Code, r/ChatGPTCoding, 2026-09-15: “worth distinguishing two different mechanisms here. telling the model "only touch these files" is a prompt-level ask - it can still wander. claude code's permissions docs are explicit that permission rules are enforced by the harness itself, not by the model choosing to comply, which is why hook/settings-based allowlists hold even when the model would otherwise improvise. if astra/codex has an equivalent hard-enforcement layer (vs. just instruction-following), that's the more reliable lever than rephrasing the prompt.” [source](https://www.reddit.com/r/ChatGPTCoding/comments/1wg06k3/how_do_you_get_astra_to_do_less/p9yhp2c/)
  - Praise, Claude Code, r/ClaudeCode, 2026-08-31: “i don't know what you people are doing wrong but i have never had claude commit and push without my prior approval. and i have built many massive projects in which he runs autonomously without needing permissions.” [source](https://www.reddit.com/r/ClaudeCode/comments/1w3lr2r/told_claude_dont_push_yet_let_me_test_it_first_it/p71pfcn/)
  - Complaint, Factory, @FactoryAI, 2026-09-11: “@ssshken @irensaltali @factoryai do you really approve every single one? just thinking about it makes me lose my mind. it asks so many questions. even claude's auto mode wears me out. i'm on the team of `--dangerously-skip-permissions` always for any harness” [source](https://twitter.com/19780871/status/2098433285143621710)

- **OpenAI Codex (mixed)**. Goal mode and selectable yolo or auto-approve settings earn praise, but users still report auto approval that fails and prompts that halt overnight runs.
  Fans like progressing without approving each command and inline questions that do not stop the task. One user values a host-enforced single confirmation before spending money. Others say auto approval hardly works, ask how to run unattended for hours, and note it hands privileged commands back to the user to run. Rivals' users ask for its one-shot yolo option.
  Evidence:
  - Praise, OpenAI Codex, X search: OpenAI Codex, Codex CLI, Codex app, 2026-09-08: “i'm impressed with the /goal of codex cli,, it progresses without needing to approve each command one by one,,” [source](https://twitter.com/4847871/status/2097268671739748588)
  - Praise, OpenAI Codex, X search: OpenAI Codex, Codex CLI, Codex app, 2026-09-22: “@youssofal_ 💯 i run codex app server for my personal agent, i can pick yolo or auto-approve depending on the task. the day after amazon blocked muse i had mine place an order on amazon start to finish. one confirmation before spending money, enforced by the host. <strict_link>” [source](https://twitter.com/1518796878753763328/status/2102372839798038721)
  - Praise, OpenAI Codex, X search: OpenAI Codex, Codex CLI, Codex app, 2026-09-23: “it seems that with codex cli, i can now answer questions inline while continuing the task. a design that stops for confirmation is not compatible with unmanned operations, so i prefer this direction of "asking without stopping." the separation of autonomous operation and mandatory confirmation is also being approached with the idea of reducing stopping points.” [source](https://twitter.com/1971311960341020672/status/2102684419479966110)
  - Praise, Factory, @droid, 2026-09-16: “oh, i was so tired at some point that i’m avoiding going back to agent babysitting. codex easily can go days, but still can hit silly permission issue at any moment :) anyway you can manage codex to push to completion, grok bot to be dangerously proactive. or use @droid to do work precisely with as least stops as possible. i gave up claude code because it still want too much attention to permissions. used to work with dangerously skipped. heard that auto review works fine. quite sure most of agents will hit a wall if you ask them to help you to change passwords or to create and use api key by itself. openclaw was first bad boy that act so proactively i’m a bit ashamed of :) let’s say i asked it to stop immediately nearly as often as ask it to continue.” [source](https://twitter.com/7344112/status/2100212921443791298)

- **Cursor (mixed)**. Auto review mode is praised for flagging risky actions with a reason, while persistence and over-asking frustrate users.
  Users say auto review reliably flags side effects and explains each flag, and like mobile approval as a control layer. Complaints cover always-allow entries that do not stick, bot integrations that keep asking despite auto-approval settings, and a sense that permission requests have grown pervasive. Some users still want a hard stop before high-stakes actions.
  Evidence:
  - Praise, Cursor, r/cursor, 2026-09-03: “it's really good it will even tell you exactly why it flagged the command right under it then you can decide” [source](https://www.reddit.com/r/cursor/comments/1w5p5xl/whats_actually_stopping_cursor_from_running/p7izn0h/)
  - Complaint, Cursor, r/cursor, 2026-09-21: “anyone had the issue where grok bot is constantly asking you to approve a task? even after putting specific instructions in that it’s okay to deploy changes, and auto approvals in the settings. quite annoying, wondering if anyone figured out a workaround” [source](https://www.reddit.com/r/cursor/comments/1wm4kom/grok_bot_constantly_asking_for_approvals/)
  - Complaint, Cursor, r/cursor, 2026-09-24: “yes, it’s very official and apparent. though the overall token counts for the $200 give me plenty of legroom each month, i’m not at all happy with the overall performances and results of the actual projects and code grok 4.7 doesn’t seem to be close to opus or astra (web and desktop versions) and when i select them as my default models, they are still well below than the companies app/web plus, though i stupidly go ahead and accept litany of permissions and authority for agents across services, something really feels overly pervasive when cursor asks these days” [source](https://www.reddit.com/r/cursor/comments/1wph9rt/downgrading_from_200_to_20/)
  - Complaint, Cursor, @cursor_ai, 2026-09-23: “@cursor_ai top of cursorbench + 40% cheaper is a shipping signal. still want a hard stop before an agent can push, buy, or blast email.” [source](https://twitter.com/2033957325631873024/status/2102766613485457556)

### Fine print

- Google Antigravity accounts for a large share of requests, so request rankings lean toward its problems.
- Most agents beyond the top five have too few posts to rate; their mentions are illustrative only.
- Some posts discuss third-party models running inside a harness, which blurs whether the agent or model caused the prompting.

## Top requests

What users ask to add or change, most asked first. 314 author-weeks ask for something. Requests do not change the Feedback Score. Rule: A separate pass by Claude Sonnet 5 reads every counted post and extracts what the author asks the agent or its vendor to add or change, with the criteria it maps to and a short normalised wording; it does not touch the labels or the Feedback Score. Claude Opus 5.5 groups the wordings within each criterion (the first criterion the request maps to) into themes; code counts them. A theme counts distinct author-weeks that ask for it, per agent; across agents, one author-week per agent. Themes asked in fewer than 2 author-weeks, and requests that share no theme, are not shown. Examples: up to 3 posts per theme from different authors, without slurs, preferring posts of 60 to 450 characters, most recent first.

| Rank | Request | Author-weeks | Posts | Agents (author-weeks) |
|---|---|---|---|---|
| 1 | Fewer permission prompts overall | 37 | 37 | Google Antigravity 16, Claude Code 8, OpenAI Codex 7, Cursor 3, OpenCode 3 |
| 2 | Auto-approve mode without permission prompts | 34 | 35 | Google Antigravity 25, OpenAI Codex 4, Claude Code 3, Cline 1, OpenCode 1 |
| 3 | Always-allow approvals that persist and work | 28 | 28 | Google Antigravity 11, Claude Code 6, OpenAI Codex 6, Cursor 3, OpenCode 2 |
| 4 | Bypass and full-access modes honored | 27 | 27 | Google Antigravity 10, Claude Code 10, OpenAI Codex 4, Cline 1, Devin 1, Kiro 1 |
| 5 | Risk-tiered granular approval policies | 20 | 21 | Google Antigravity 6, Claude Code 4, OpenAI Codex 4, GitHub Copilot 3, Cursor 1, Devin 1, Kiro 1 |
| 6 | Model-based automatic review of commands | 18 | 18 | Google Antigravity 10, Claude Code 3, OpenAI Codex 3, Devin 1, OpenCode 1 |
| 7 | Confirmation before destructive or sensitive actions | 16 | 16 | Claude Code 7, OpenAI Codex 4, Google Antigravity 3, Cursor 1, OpenCode 1 |
| 8 | Skip prompts for low-risk read-only commands | 14 | 14 | Google Antigravity 8, Claude Code 4, OpenAI Codex 1, OpenCode 1 |
| 9 | Audit logs for agent actions | 10 | 10 | Claude Code 3, Cursor 3, Google Antigravity 1, OpenAI Codex 1, Factory 1, OpenCode 1 |
| 10 | Restrictive default-deny scoped permissions | 9 | 9 | Claude Code 3, OpenAI Codex 2, Devin 2, Cursor 1, Zed 1 |
| 11 | Command allowlist with wildcard patterns | 8 | 8 | Google Antigravity 6, Claude Code 2 |
| 12 | Easy persistent toggle for auto mode | 7 | 8 | Google Antigravity 4, Claude Code 1, OpenAI Codex 1, Devin 1 |

### 1. Fewer permission prompts overall

- OpenAI Codex, 2026-09-26, r/codex (Reddit): “it's stupid as well asking permissions to this and that, anything but to proceed, when i have clearly said fix everything lol.” [source](https://www.reddit.com/r/codex/comments/1sr8j8b/codex_keeps_stopping_every_30_to_45_seconds_and/pc4iwfw/)
- Cursor, 2026-09-24, @cursor_ai (X): “@cursor_ai i don't understand how i can stop getting buried in approval requests! <strict_link>” [source](https://twitter.com/905512466339287040/status/2103098476464595397)
- Claude Code, 2026-09-24, @ClaudeDevs (X): “@claudedevs estou gostando de trabalhar na nuvem, mas precisa melhorar as permissões. ter que ficar mandando mensagem pra pedir pro "claude computador" fazer trava a produção.” [source](https://twitter.com/3775511057/status/2102942524520227249)

### 2. Auto-approve mode without permission prompts

- Google Antigravity, 2026-09-26, r/google_antigravity (Reddit): “it’s shit if you use headless mode, it cannot have auto-approve. i had to use tmux to have an active interactive session if i want auto-approve, otherwise it asks for permission for every single step😅. but yea, remote-control is so good, it’s great that it’s an pwa, no apps required. (as long as you don’t mind having your session data in the cloud, personal plan doesn’t have zdr anyways)” [source](https://www.reddit.com/r/google_antigravity/comments/1wqmd4n/why_is_the_antigravitycli_so_underrated/pc5zqs8/)
- Google Antigravity, 2026-09-26, r/google_antigravity (Reddit): “but that’s not what i am asking for though. what i am saying is that there should be a similar command to /yolo from codex in agy-cli. basically a temporary one prompt —dangerously-skip-permissions and when the prompt is finished processing it goes to defaults. none current options do this, you either set it for an entire session or globally.” [source](https://www.reddit.com/r/google_antigravity/comments/1wqbyzk/antigravity_cli_release_v127_v1211/pc4vris/)
- OpenAI Codex, 2026-09-24, r/codex (Reddit): “starting codex for the first time [manually approving codex prompts \(ai generated image\)](<strict_link>) today i started codex for the first time (i used a lot claude code) and directly launch a fleet of agents and it was a bad idea.... i expected at least to see the "auto-mode" equivalent in the tui. now i am pressing "approve" like back in 2025.” [source](https://www.reddit.com/r/codex/comments/1wpehp7/starting_codex_for_the_first_time/)

### 3. Always-allow approvals that persist and work

- Google Antigravity, 2026-09-26, @antigravity (X): “@rodydavis @antigravity the constantly asking for the same class of permission you've already approved several times over going in circles, it doesn't complete the work given only does like 60% and it's not even a oneshot prompt” [source](https://twitter.com/1895520405885952000/status/2103773104593945021)
- Google Antigravity, 2026-09-26, @antigravity (X): “@antigravity why can't you even handle the most basic command-line authorization? i've clearly authorized all git commands and other commands for the entire project, yet i keep having to authorize everything again and again” [source](https://twitter.com/1559895451805286401/status/2103657920911327482)
- OpenAI Codex, 2026-09-25, r/google_antigravity (Reddit): “am i the only one for whom "antigravity" never actually "always proceeds"? no matter what i change in the workspace settings, it always asks for countless confirmations; even when i select the option to always allow access for the folder or project, it keeps asking the same questions. does anyone know how to configure this, or is there an update that includes an "always proceed" feature like in codex or claude code?” [source](https://www.reddit.com/r/google_antigravity/comments/1wpkgy1/why_always_proceed_never_work/)

### 4. Bypass and full-access modes honored

- Google Antigravity, 2026-09-26, r/google_antigravity (Reddit): “those don't work on windows. it always asks regardless. you can throw it into turbo mode and it'll still ask. <strict_link>” [source](https://www.reddit.com/r/google_antigravity/comments/1wpkgy1/why_always_proceed_never_work/pc5jqpu/)
- Claude Code, 2026-09-26, @ClaudeDevs (X): “@claudedevs i'm already in bypass permissions / auto mode, just allow this shit stop asking me <strict_link>” [source](https://twitter.com/212418463/status/2103956882339594574)
- Google Antigravity, 2026-09-20, @antigravity (X): “@antigravity for windows is unusable. even in the cli. an endless stream of permission requests even with --mode accept-edits on. every single tool use. just going to stop here and cancel it. i like the new 3.8 flash model, its honestly underrated, but its just not user friendly.” [source](https://twitter.com/402285185/status/2101494705066500569)

### 5. Risk-tiered granular approval policies

- Kiro, 2026-09-24, @kirodotdev (X): “@dynatrace @kirodotdev @awscloud @blueboxhq an agent fixing code should know how it behaves in production. i'd want clear rules on what it can inspect and when it needs permission to change something. great discussion for my show: <strict_link>” [source](https://twitter.com/35203319/status/2102936869524656177)
- Google Antigravity, 2026-09-16, @antigravity (X): “@antigravity how about introducing a secondary, specialised model that does the approval for me and to which i can tell the rule in plain english, like "do not allow accessing other than the project dir and ~/some/related/dir. the agent can access the web but file upload is prohibited"?” [source](https://twitter.com/1664456551967633409/status/2100014501408227501)
- OpenAI Codex, 2026-09-13, r/codex (Reddit): “it's so dumb that they make us choose between "ask for approval" and "approve everything". how about "approve everything except `rm -rf`, then ask for approval"? knowing them they'd make a crappy version which asks for permission whenever it deletes anything, including deleting a temporary file that it creates itself while working on a problem. that would still be too annoying to use!” [source](https://www.reddit.com/r/codex/comments/1wep1ii/truly_heed_the_warning_of_56_sol_deleting_your/p9gnk03/)

### 6. Model-based automatic review of commands

- OpenCode, 2026-09-20, @opencode (X): “@thdxr @opencode i heard you were considering adding jev to go, but what do you think about a native integration for an intelligent auto-permissions mode? instead of blanket rules it would be nice to classify based on request context and defaults to allow / deny / escalate.” [source](https://twitter.com/1591863582643339264/status/2101697642254532882)
- Google Antigravity, 2026-09-20, @antigravity (X): “i enjoyed the speed of flash in @antigravity but really missed the auto classifier found in others. @typesafeai ‘s jev was perfect combined with a rust based hook to do the permission classification really fast: <strict_link>” [source](https://twitter.com/740931661723017216/status/2101637185384407139)
- Devin, 2026-09-18, @DevinAI (X): “@januarycomputer @jjacky i paid 20 bucks to try @devinai and haven't used any of it because the smart permissions doesn't work in the desktop interface, it kept stopping to ask approval for nothing, and i can't be fucked to fiddle with it and just cutting my losses.” [source](https://twitter.com/46284019/status/2100824388212035795)

### 7. Confirmation before destructive or sensitive actions

- Claude Code, 2026-09-26, r/ClaudeCode (Reddit): “all guards for commands that could edit and delete stuff too so they have to be manually approved” [source](https://www.reddit.com/r/ClaudeCode/comments/1wquoxy/fable_51_live_vehicle_diagnostics/pc8iq6a/)
- OpenAI Codex, 2026-09-25, r/codex (Reddit): “sending emails should be a deterministic process. if you wanted to use codex for this you should've had it at least make a page where you click a button and sign off on the action.” [source](https://www.reddit.com/r/codex/comments/1wq06yi/6_sol_is_bad_what_it_just_did/pc144o5/)
- Claude Code, 2026-09-23, @ClaudeDevs (X): “@bcherny @claudedevs in claude code auto mode, when a certain action gets blocked, say terraform apply, claude would start looking for workaround, fail and later give me a command to run myself. ideally i want that it stops and asks for approval. how do i achieve this?” [source](https://twitter.com/2915473418/status/2102786446591709488)

### 8. Skip prompts for low-risk read-only commands

- Google Antigravity, 2026-09-18, r/GoogleAntigravityIDE (Reddit): “yes. it's really bad. to the point i cannot get it to work at all with regex or wildcards. git log, git diff git grep.. for read operations i don't care about the rest of what it does. but it asks me every time no matter what i do claude is so much better with this.” [source](https://www.reddit.com/r/GoogleAntigravityIDE/comments/1pzdjtd/allowdeny_commands_list_is_bad/pao6meb/)
- Google Antigravity, 2026-09-18, @antigravity (X): “why 20+ approvals needed? git all read-only commands can be approved at once? could you make it easy like others already have? please advise. @antigravity @_mohansolo @_anshulr <strict_link>” [source](https://twitter.com/1510027424/status/2100931212063985691)
- Google Antigravity, 2026-09-15, r/google_antigravity (Reddit): “<strict_link> i keep seeing it asking for approval for running the simplest commands. i want it auto-approve these things for me so i can leave it running in the background. it's vert annoying that it cannot funcntion for 5 seconds without me being aroung to click on yes always allow this, for the 1000th time.” [source](https://www.reddit.com/r/google_antigravity/comments/1wgwlct/how_to_let_it_autoapprove_commands_i_trust_it/)

### 9. Audit logs for agent actions

- Cursor, 2026-09-20, @cursor_ai (X): “@cursor_ai scheduled agents can turn project work into a continuous feedback loop: watch signals, propose a fix, and keep humans in the approval path. per-task permissions plus an audit trail will be essential when automation touches slack, ci, and production-adjacent systems.” [source](https://twitter.com/1208933549081907200/status/2101777299943174293)
- Cursor, 2026-09-19, @cursor_ai (X): “@cursor_ai @bot persistent threads are very suitable for project context, but "agents always online" can also bring cost and permission boundary issues. i hope to see clear activity logs, budget limits, and when human confirmation is required.” [source](https://twitter.com/2259799350/status/2101377926855803235)
- Factory, 2026-09-18, @FactoryAI (X): “@kitsunekode @tereza_tizkova @factoryai the permission layer is the bit i’d obsess over first. hands-free is great, but every tool call needs a clear preview, stop button, and a tiny log you can actually skim later.” [source](https://twitter.com/2096781123321819137/status/2100910699140596083)

### 10. Restrictive default-deny scoped permissions

- Zed, 2026-09-25, @zeddotdev (X): “@zeddotdev the useful bit isn't the kill switch, it's the blast-radius clarity. a single setting that also removes mcp and external agents is good incident hygiene, but teams will still want per-project policy instead of an all-or-nothing switch.” [source](https://twitter.com/1734829438364200960/status/2103322080280219993)
- Claude Code, 2026-09-24, @ClaudeDevs (X): “@claudedevs 로컬 실행이 가능해질수록 프로젝트별 파일·셸·네트워크 권한을 기본 거부하고, 스레드별 diff와 실행 로그를 남겨야 병렬 작업이 편해져도 사고 범위를 통제할 수 있습니다.” [source](https://twitter.com/1619634971848892418/status/2102983921353052556)
- Devin, 2026-09-21, @cognition (X): “@cognition verification is the permission boundary. give agents write access only after tests, types, and policy checks fail loudly.” [source](https://twitter.com/2099871292480421888/status/2102126392561352894)

### 11. Command allowlist with wildcard patterns

- Google Antigravity, 2026-09-24, r/google_antigravity (Reddit): “how can i allow commands like "select-string" (git grep, etc.) for any files? i tried adding "select-string" and "select-string \*" in "terminal commands", but it keeps asking me to allow "select-string" commands. i don’t want to repeatedly add "select-string file1" or "select-string file2".” [source](https://www.reddit.com/r/google_antigravity/comments/1wp4lqz/vscode_plugin_how_can_you_enable_commands_like/)
- Google Antigravity, 2026-09-20, @antigravity (X): “why isn’t there an option to just whitelist `find` @antigravity <strict_link>” [source](https://twitter.com/1770675285584744448/status/2101535358722641950)
- Google Antigravity, 2026-09-11, @antigravity (X): “@googledevs @antigravity how about a good "always allow" permission system? i'm not yoloing, i want to allow all "git diff" commands not each one at the time... "git diff agents.md", "git diff <strict_link>", "git diff spec.md", etc” [source](https://twitter.com/376293797/status/2098539464356495543)

### 12. Easy persistent toggle for auto mode

- Google Antigravity, 2026-09-16, @antigravity (X): “@antigravity fix you antigravity cli permission system. its not usable without starting with --dangerously-skip-permission” [source](https://twitter.com/1930980182434959360/status/2100200161972527293)
- Google Antigravity, 2026-09-03, r/google_antigravity (Reddit): “thanks. i miss the yolo toggle just/yolo turn it on, and then use it again to turn it off” [source](https://www.reddit.com/r/google_antigravity/comments/1w69qmt/finally_someone_popular_bringing_attention_to/p7lu49p/)
- Google Antigravity, 2026-09-03, r/google_antigravity (Reddit): “yes, but you understand that it's a shame to have to type "—dangerously-skip-permissions" to launch automatically. if we forget, we have to kill and relaunch, which is a shame and could easily be implemented on your side. thank you for /learn and /generative_ui, i wasn't aware!” [source](https://www.reddit.com/r/google_antigravity/comments/1w5h7wb/bruh_didnt_expect_gemini_flash_to_top_deepswe/p7jk3uu/)

## Every agent

| Agent | Overall rank | Reading | Customer love | 95% interval | n | Praise | Complaint |
|---|---|---|---|---|---|---|---|
| [OpenAI Codex](https://feedbackbench.com/agents/codex.md) | 2 | Typical | 0.530 | 0.494–0.565 | 203 | 61 | 142 |
| [Claude Code](https://feedbackbench.com/agents/claude-code.md) | 1 | Typical | 0.523 | 0.490–0.552 | 257 | 73 | 184 |
| [Cursor](https://feedbackbench.com/agents/cursor.md) | 4 | Typical | 0.505 | 0.475–0.532 | 37 | 10 | 27 |
| [OpenCode](https://feedbackbench.com/agents/opencode.md) | 3 | Typical | 0.495 | 0.470–0.525 | 32 | 7 | 25 |
| [Google Antigravity](https://feedbackbench.com/agents/antigravity.md) | =5 | Worse than peers | 0.405 | 0.374–0.437 | 186 | 21 | 165 |
| [Pi](https://feedbackbench.com/agents/pi.md) | 7 | Too few posts | – | – | 13 | 10 | 3 |
| [GitHub Copilot](https://feedbackbench.com/agents/copilot.md) | =8 | Too few posts | – | – | 11 | 3 | 8 |
| [Devin](https://feedbackbench.com/agents/devin.md) | =5 | Too few posts | – | – | 9 | 1 | 8 |
| [Cline](https://feedbackbench.com/agents/cline.md) | =8 | Too few posts | – | – | 4 | 1 | 3 |
| [Factory](https://feedbackbench.com/agents/factory.md) | =11 | Too few posts | – | – | 4 | 2 | 2 |
| [Zed](https://feedbackbench.com/agents/zed.md) | =8 | Too few posts | – | – | 3 | 0 | 3 |
| [Kiro](https://feedbackbench.com/agents/kiro.md) | 13 | Too few posts | – | – | 3 | 0 | 3 |
| [Amp](https://feedbackbench.com/agents/amp.md) | =11 | Too few posts | – | – | 2 | 1 | 1 |
| [Conductor](https://feedbackbench.com/agents/conductor.md) | 14 | Too few posts | – | – | 0 | 0 | 0 |
| [Warp](https://feedbackbench.com/agents/warp.md) | 15 | Too few posts | – | – | 0 | 0 | 0 |
| [Grok Build](https://feedbackbench.com/agents/grok-build.md) | 16 | Too few posts | – | – | 0 | 0 | 0 |
| [Augment Code](https://feedbackbench.com/agents/augment.md) | 17 | Too few posts | – | – | 0 | 0 | 0 |

## Posts

Receipts rule: The 5 most recent praise and complaint posts per area (first 700 characters) and 3 per criterion (first 450 characters).

### OpenAI Codex

- Praise, 2026-09-26, r/google_antigravity (Reddit): “btw, would be great to have a /yolo or something similar in cli as well for a one-time usage without any safety guards or rails and permission prompts just like codex.” [source](https://www.reddit.com/r/google_antigravity/comments/1wqbyzk/antigravity_cli_release_v127_v1211/pc45ef6/)
- Praise, 2026-09-26, r/google_antigravity (Reddit): “but that’s not what i am asking for though. what i am saying is that there should be a similar command to /yolo from codex in agy-cli. basically a temporary one prompt —dangerously-skip-permissions and when the prompt is finished processing it goes to defaults. none current options do this, you either set it for an entire session or globally.” [source](https://www.reddit.com/r/google_antigravity/comments/1wqbyzk/antigravity_cli_release_v127_v1211/pc4vris/)
- Praise, 2026-09-25, r/codex (Reddit): “same, i prefer that it raises blockers, like a missing .env file that i should probably write. it has a realistic balance between security, raising blockers when necessary, and not running through walls with hallucinated assumptions.” [source](https://www.reddit.com/r/codex/comments/1worwfr/sol_6_was_insufferable_glad_to_be_back_to_56/pbwhgr7/)
- Complaint, 2026-09-27, r/codex (Reddit): “two weeks later: we have optimized our new models. they have even less token usage. resulting in you needing a $10,000 subscription to make it the entire week and also the models refuse to work at all and ask you to run commands for them.” [source](https://www.reddit.com/r/codex/comments/1wr1oir/they_are_aware_and_working_on_it_apparently_just/pc9uydq/)
- Complaint, 2026-09-27, r/codex (Reddit): “codex decided to code outside project folder. i will never use codex again.... im too dumb to find proper logs to send to codex so they can see the loophole the chatgpt used to code but basically it: "what are you doing???????????????????????? how you got access to opus55 folder?????????? 12:51worked for 19si’ve stopped making changes. the filesystem tools allowed reading outside this chat’s working folder. i searched nearby folders, found opus55” [source](https://www.reddit.com/r/codex/comments/1wre9dq/codex_usage_vs_claude/pcc8rhj/)
- Complaint, 2026-09-27, r/codex (Reddit): “do i really want a clanker that's always burning my usage on stuff that i don't trust it to handle without me?” [source](https://www.reddit.com/r/codex/comments/1wrn697/new_openai_product_o_but_not_for_plus_users/pcdu1ej/)

### Claude Code

- Praise, 2026-09-27, r/AI_Agents (Reddit): “anti gravity doesn’t have an auto mode like claude code, which means even for basic execution i have to be present and press i accept. the gemini models have very bad code output in comparisons to claude or codex. i’m talking 4.6 being much better than whatever newer pro or flash models are. it is fine for quick work but not for complex tasks” [source](https://www.reddit.com/r/AI_Agents/comments/1wrxqx1/why_is_google_antigravity_so_underrated/pcgs5a5/)
- Praise, 2026-09-26, r/ClaudeCode (Reddit): “the fact that not responding means denying is the best default of the project, and it is also exactly how my family works, so i already know the interface.” [source](https://www.reddit.com/r/ClaudeCode/comments/1wqs9oa/running_my_claude_code_sessions_from_whatsapp_and/pc6j9m8/)
- Praise, 2026-09-26, r/ClaudeCode (Reddit): “fair question. the awake bit was a requirement i wanted to be upfront about. isle still needs the mac running. the part i'm building is reviewing and answering the approval right in the notch while you're working in another app, with the same place for claude code, codex and cursor requests. if you only use claude and its app already handles this well for you, there may not be much reason to add isle. i should have made that distinction clearer i” [source](https://www.reddit.com/r/ClaudeCode/comments/1wma6ma/weekly_showcase_thread_what_are_you_building_with/pc7l5lk/)
- Complaint, 2026-09-27, r/ClaudeCode (Reddit): “your typed approval workaround also avoids a nasty tradeoff in the linked issue. the reporter says \`claude\_code\_child\_session=1\` suppresses the relay, but disables transcript saving/resume unless paired with another override. even then, it still drops prompt history. to keep typing to a minimum, have the queue script print a single approval line listing the selected lanes and allowed actions, ready to paste as your next message. you still ne” [source](https://www.reddit.com/r/ClaudeCode/comments/1wr8cw1/claude_code_workflow_harness_change/pccy35j/)
- Complaint, 2026-09-27, r/ClaudeCode (Reddit): “the school emails → calendar → whatsapp reminder chain is great. that's exactly the kind of boring daily friction worth automating. mine: i kept losing track of which claude code session was done and which one was sitting there waiting for my permission. so i built a small mac app that lives in the macbook notch. hover over it and you see every session and what it's doing, and the notch lights up when one needs me. it also has a little pixel offi” [source](https://www.reddit.com/r/ClaudeCode/comments/1wrcmjn/what_tool_have_you_built_for_yourself_with_claude/pcf0w96/)
- Complaint, 2026-09-27, r/ClaudeCode (Reddit): “this is the second time recently that a change server-side by anthropic has broken my system, and this one has no mention in the changelogs on their github so i thought i'd bring it here. my workflows, as i'm sure many of yours are, require an explicit "go" permission. until today, that permission could be given from an askuserprompt. my system is set up so that i barely use typed responses. a fair number of sessions only have my opening launch w” [source](https://www.reddit.com/r/ClaudeCode/comments/1wr8cw1/claude_code_workflow_harness_change/)

### Cursor

- Praise, 2026-09-27, @cursor_ai (X): “@mikegeorg @falktg @bot @cursor_ai pspad still holding strong after 25 years is impressive. pairing that reliable base with grok and cursor for structured, controlled server work keeps the human firmly in charge of every step.” [source](https://twitter.com/1720665183188922368/status/2104122224290451704)
- Praise, 2026-09-25, r/cursor (Reddit): “that record-only day is a great calibration step. i like separating path checks from phrase checks, then narrowing both from real events before enabling blocks. the six self-inflicted stops are exactly the kind of noise i would want to remove first. i will try the same approach on the next protected-path change.” [source](https://www.reddit.com/r/cursor/comments/1wn2j3q/i_stopped_pasting_huge_rules_into_every_agent/pbx6dxd/)
- Praise, 2026-09-25, r/cursor (Reddit): “not even going to click that cursor gives you a confirmation prompt when working outside project files pebcak and reading that thread would be a waste of my valuable vibecoding time” [source](https://www.reddit.com/r/cursor/comments/1wq0bdq/cursor_wiped_out_a_guys_entire_drive/pc10kig/)
- Complaint, 2026-09-25, r/cursor (Reddit): “he describes how he deleted his backup recently so he could make a new one in the future funnily enough, cursor would ask me for permission when ever it does something, but opening the command preview does not work on my machine so i just tell it to proceed already” [source](https://www.reddit.com/r/cursor/comments/1wq0bdq/cursor_wiped_out_a_guys_entire_drive/pc1cf9c/)
- Complaint, 2026-09-24, r/cursor (Reddit): “yes, it’s very official and apparent. though the overall token counts for the $200 give me plenty of legroom each month, i’m not at all happy with the overall performances and results of the actual projects and code grok 4.7 doesn’t seem to be close to opus or astra (web and desktop versions) and when i select them as my default models, they are still well below than the companies app/web plus, though i stupidly go ahead and accept litany of perm” [source](https://www.reddit.com/r/cursor/comments/1wph9rt/downgrading_from_200_to_20/)
- Complaint, 2026-09-24, @cursor_ai (X): “@cursor_ai i don't understand how i can stop getting buried in approval requests! <strict_link>” [source](https://twitter.com/905512466339287040/status/2103098476464595397)

### OpenCode

- Praise, 2026-09-23, @opencode (X): “@trq212 i just use it to make sure the agent won't change files. i'm an @opencode user” [source](https://twitter.com/798021536/status/2102826737663189421)
- Praise, 2026-09-23, r/ChatGPTCoding (Reddit): “i found that opencode with strict permissions work the best.” [source](https://www.reddit.com/r/ChatGPTCoding/comments/1wnwmia/chatgpt_sol_6_used_local_qwen_for_heavy_lifting/pbmxes9/)
- Praise, 2026-09-18, r/opencode (Reddit): “i use it daily and it doesn't seem stupid to me, it always asks me for permission if it needs to do something destructive. obviously, permissions and instructions need to be configured, otherwise it's like rolling a die.” [source](https://www.reddit.com/r/opencode/comments/1wjjqvr/muse_13_free_formatted_my_drive/paj9wkv/)
- Complaint, 2026-09-27, @opencode (X): “@superalesha @opencode @openrouter it is very effective but i’ve realized one problem. its very hard to convince it that the reason for a certain problem is certain something. it likes to do its own analysis even tho if you said the opposite and doesn’t really ask for permission to do what it thinks is right.” [source](https://twitter.com/2027776550402408448/status/2104178728922447941)
- Complaint, 2026-09-27, @opencode (X): “@opencode beware. that shitty model is asking me to access my ssh file constantly, when it is not necessary to achieve the task.” [source](https://twitter.com/1550629490279284736/status/2104224895609741468)
- Complaint, 2026-09-20, r/opencode (Reddit): “i'm on windows 11 , last version, terminal client. i'm aware that big pickle explicitly asks for any permission for what it needs. it was nice and clean. then i read that it's a good idea to change models between planning and building, and read that nemotron was actually quite good,so i tried with that model too. the first thing it did after i started the conversation prompting for planning a python plug-in, was to take access to c:\\ and ta” [source](https://www.reddit.com/r/opencode/comments/1wl4t5x/is_it_normal_that_a_given_model_takes_access_to/)

### Google Antigravity

- Praise, 2026-09-27, @antigravity (X): “@antigravity the approval step is what sells it honestly. most tools say theyll "think" then just run wild with whatever they guessed.” [source](https://twitter.com/500606751/status/2104064825836134536)
- Praise, 2026-09-25, r/google_antigravity (Reddit): “how do people get this to happen. my agents file has strict rules, it doesn't do anything i don't approve or is not in a plan” [source](https://www.reddit.com/r/google_antigravity/comments/1wpl0y7/50gb_data_wipe_out_from_hard_drive/pbx8q2q/)
- Praise, 2026-09-21, @antigravity (X): “@clemensscharti @typesafeai @antigravity yeah, this is a much cleaner boundary. 👍 user intent can remove the annoying confirmations for things they actually asked for, without becoming a blanket pass. catastrophic ops still stopping for confirmation feels right.” [source](https://twitter.com/2093701769696088064/status/2102077129374490683)
- Complaint, 2026-09-27, @antigravity (X): “@antigravity i believe that it is important to get approval before execution rather than just making a plan. it would be better if we could also check the changes again when the plan changes after approval.” [source](https://twitter.com/2978197789/status/2104080470883614974)
- Complaint, 2026-09-26, r/google_antigravity (Reddit): “btw, would be great to have a /yolo or something similar in cli as well for a one-time usage without any safety guards or rails and permission prompts just like codex.” [source](https://www.reddit.com/r/google_antigravity/comments/1wqbyzk/antigravity_cli_release_v127_v1211/pc45ef6/)
- Complaint, 2026-09-26, r/google_antigravity (Reddit): “but that’s not what i am asking for though. what i am saying is that there should be a similar command to /yolo from codex in agy-cli. basically a temporary one prompt —dangerously-skip-permissions and when the prompt is finished processing it goes to defaults. none current options do this, you either set it for an entire session or globally.” [source](https://www.reddit.com/r/google_antigravity/comments/1wqbyzk/antigravity_cli_release_v127_v1211/pc4vris/)

### Pi

- Praise, 2026-09-23, r/PiCodingAgent (Reddit): “i did try this, and it's by far the best strategy i've tried. i took a pretty heavy handed approach of removing all write permissions just to see how it felt. i'm curious what sort of permissions you give your orchestrator by default and if there are ways to toggle between "profiles" for the orchestrator if you want to shift quickly to the more vanilla single agent workflow” [source](https://www.reddit.com/r/PiCodingAgent/comments/1wo6lr8/how_to_better_enforce_subagent_delegation/pbnukne/)
- Praise, 2026-09-22, r/PiCodingAgent (Reddit): “sandbox? no. tool guard? most certainly.” [source](https://www.reddit.com/r/PiCodingAgent/comments/1wnl3gk/do_you_use_the_sandbox_extension_is_it_really/pbfv8dd/)
- Praise, 2026-09-20, r/PiCodingAgent (Reddit): “hi there, i really love pi's approach to security with "figure it out yourself, yolo by design", so i did. that thing is still yolo, but sandboxed. dead simple 2 files: `dockerfile` (the thing itself) and `justfile` (fancy makefile to run the thing). don't mind the repo just created - i'm using it for a while, just decided it's good enough to publish now, some notes to avoid misunderstanding: * why "it is so dangerous"? - thanks /r/amodei, he's s” [source](https://www.reddit.com/r/PiCodingAgent/comments/1wlvtpu/it_is_so_dangerous_sandbox/)
- Complaint, 2026-09-22, r/PiCodingAgent (Reddit): “i have been using the sandbox extension for quite a while, but i am a bit fed up with having to approve stuff manually all the time. i know the pain may be worth it to avoid an agent doing some nefarious stuff with your data, but sometimes i just want to delete it and leave the agent working on its own. so what i essentially want to know is this: have you run into significant issues for not having a sandbox?” [source](https://www.reddit.com/r/PiCodingAgent/comments/1wnl3gk/do_you_use_the_sandbox_extension_is_it_really/)
- Complaint, 2026-09-17, r/PiCodingAgent (Reddit): “great contribution, i'm new to pi and its permissions setup was bugging me, and i just got access to jev. i hope i can try it soon.” [source](https://www.reddit.com/r/PiCodingAgent/comments/1wimfhg/piwarden_a_jevpowered_second_pair_of_eyes_for_pi/pabm1f2/)
- Complaint, 2026-09-14, r/PiCodingAgent (Reddit): “8gb of vram so my options are limited. 3.6 runs but albeit slow. llmstudio had it contained but pi just gave it all the privileges. which i didn’t catch. so my fault there.” [source](https://www.reddit.com/r/PiCodingAgent/comments/1wg0h5p/it_deleted_my_files/p9qikxi/)

### GitHub Copilot

- Praise, 2026-09-25, r/GithubCopilot (Reddit): “this week i’ve been using copilot / interactive / assisted approvals. it’s been very pleasant after feeling like i was fighting with local more recently” [source](https://www.reddit.com/r/GithubCopilot/comments/1wpctlc/vs_code_chat_users_local_or_copilot_harness/pbx3k2v/)
- Praise, 2026-09-04, r/GithubCopilot (Reddit): “swap over to the 'copilot' host, and use assisted permissions. way better.” [source](https://www.reddit.com/r/GithubCopilot/comments/1w78bm8/vscode_autopilot_is_too_auto/p7t0pb3/)
- Praise, 2026-09-03, r/devops (Reddit): “i'm using copilot cli and what i've done is configure the pretooluse hook. i've made a list of commands and paths which will always be denied regardless of its current permissions. and for a subset of commands it must always request permission. furthermore i've made a small application that monitors all the events made by the ai so i can always have a look at what was executed during a given session. and of course stated in the instructions that” [source](https://www.reddit.com/r/devops/comments/1w5p8cl/anyone_else_nervous_about_what_coding_agents_can/p7ir5wi/)
- Complaint, 2026-09-20, r/GithubCopilot (Reddit): “thanks for your response. we aren't using device policies yet, we have only disabled agent mode on the ghec portal, but vs looks like it bypasses this because even in interactive/ask mode it will make wholesale changes to multiple files in the workspace if you ask it to, which is currently not permitted at work. what's frustrating is i'm seeing different behaviour between vs 2022 and vs 2026 so they're using different versions of github copilot” [source](https://www.reddit.com/r/GithubCopilot/comments/1win2b6/github_copilot_is_a_nightmare_for_enterprises/pawvff3/)
- Complaint, 2026-09-17, r/GithubCopilot (Reddit): “now have 100 software, platform engineers, front end devs and artists on business and have the same problem. cli has some permissions. ides others. github copilot app others again. organisations claim to provide granular control, but we're just not experiencing it.” [source](https://www.reddit.com/r/GithubCopilot/comments/1win2b6/github_copilot_is_a_nightmare_for_enterprises/pabr4iq/)
- Complaint, 2026-09-13, @GitHubCopilot (X): “oofduh, switching from working on personal projects in @openaicodexcli to work projects in @githubcopilot is painful. a lot of hand holding and button pushing.” [source](https://twitter.com/1632699243231051777/status/2099227015815512232)

### Devin

- Praise, 2026-09-26, @cognition (X): “@cognition scoped perms in teams beats "just give devin the whole inbox" every day.” [source](https://twitter.com/2080615683902337024/status/2103730870171709918)
- Complaint, 2026-09-25, G2 (G2): “q: what problems is the product solving and how is that benefiting you? a: for ebiquity, i see the most value for data and engineering teams by reducing repetitive development, debugging and maintenance work. it could help teams move through smaller backlog tasks faster while allowing developers to focus on more complex work. q: what do you like best about the product? a: devin can take a development task from the initial request through coding,” [source](https://www.g2.com/products/devin-ai/reviews/devin-ai-review-13609931)
- Complaint, 2026-09-23, @cognition (X): “@cognition devin mentioning coworkers is the real change here. the first time it pings someone at 2am about a flaky test, the person getting pinged has no way to know if a human thought it was worth the interruption” [source](https://twitter.com/2032890486571372544/status/2102824613239767041)
- Complaint, 2026-09-19, @cognition (X): “@cognition $75 is the screenshot. a card with no permission model is just a faster way to learn what the agent spent.” [source](https://twitter.com/1524807864082120704/status/2101366426250465595)

### Cline

- Praise, 2026-09-22, r/CLine (Reddit): “the entire reason i use cline in the first place is because it has light guardrails that let you get straight to building.” [source](https://www.reddit.com/r/CLine/comments/1wnluat/qwen_38_flash_next_broke_out_of_plan_mode_vscode/pbgmpyg/)
- Complaint, 2026-09-18, @cline (X): “@cline is being dumb. "proceed while running" shouldn't even show up when it's on auto-approve. and, it's "whilst". "while" is a period of time, as in "i'll be a while"” [source](https://twitter.com/1416864353131765762/status/2101021865888383202)
- Complaint, 2026-09-14, @cline (X): “@cline worth asking about the scheduled runs. a nightly security scan reads advisories and dependency changelogs, which is text an attacker can write into. at 3am nobody is sitting on the approval step. what stops the run acting on instructions inside the input it was told to read?” [source](https://twitter.com/1577726234066157570/status/2099611771418071117)
- Complaint, 2026-09-10, @cline (X): “why does rejecting a permission terminate the entire ai coding session? if i reject access to .env, why not just skip that action and continue? a rejection should mean “don’t do this”, not “terminate the session.” @opencode @claudeai #ai #llm #dev @pidotdev @cline” [source](https://twitter.com/2606068855/status/2097893806230393139)

### Factory

- Praise, 2026-09-16, @droid (X): “oh, i was so tired at some point that i’m avoiding going back to agent babysitting. codex easily can go days, but still can hit silly permission issue at any moment :) anyway you can manage codex to push to completion, grok bot to be dangerously proactive. or use @droid to do work precisely with as least stops as possible. i gave up claude code because it still want too much attention to permissions. used to work with dangerously skipped. heard” [source](https://twitter.com/7344112/status/2100212921443791298)
- Praise, 2026-09-16, @droid (X): “@orange_boy @samueljmcd @droid being tired before you even reopen the agent says enough. i give each rerun job only the connections it needs up front, so it runs without finding a new permission halfway through. i'm not on standby for the next popup. <strict_link>” [source](https://twitter.com/1708040539407269888/status/2100223881005211820)
- Complaint, 2026-09-11, @FactoryAI (X): “@irensaltali @yigitkonur @factoryai worth knowing where they go. i ran a single-page week planner through it and planning alone took 41 minutes and 7 of the 50 credits, before any code. most of the friction was permission dialogs, 32 allow clicks out of 54 total actions.” [source](https://twitter.com/1909713300868280320/status/2098413898353217579)
- Complaint, 2026-09-11, @FactoryAI (X): “@ssshken @irensaltali @factoryai do you really approve every single one? just thinking about it makes me lose my mind. it asks so many questions. even claude's auto mode wears me out. i'm on the team of `--dangerously-skip-permissions` always for any harness” [source](https://twitter.com/19780871/status/2098433285143621710)
- Complaint, 2026-09-11, @FactoryAI (X): “for the run, yes, every one, because the whole point was counting what a person actually does out of the box. skipping them would have measured my setup instead of the tool. day to day i'd do the same as you. which is its own finding: the default for these is a flow nobody keeps, so the real number is either 54 actions or a flag that turns the guardrails off entirely.” [source](https://twitter.com/1909713300868280320/status/2098500898737528870)

### Zed

- Complaint, 2026-09-24, @zeddotdev (X): “@zeddotdev yes because i hate it when the ai goes and makes changes when i was just trying to discuss” [source](https://twitter.com/1361615777300762629/status/2102974332355977570)
- Complaint, 2026-09-22, @zeddotdev (X): “@paul_dentro @zeddotdev maybe.. i couldn't really figure it out, i also dont like running agents from within the ide?” [source](https://twitter.com/64919582/status/2102527159713907193)
- Complaint, 2026-09-21, r/google_antigravity (Reddit): “was ide. but that seems to be dead now. so tried the vscode extensions. which seemed good, then went a bit weird and slow... tried zed with extensions and although i miss the interactivish implementation plans, the functionality seems waaay faster and responsive as a tool. just struggling with nailing down the right balance of allowable actions so i'm not constantly clicking allow. its frustrating that even though it has a dedicated extension, th” [source](https://www.reddit.com/r/google_antigravity/comments/1wluoqe/which_antigravity_surface_do_you_use_the_most/pb5j7fo/)

### Kiro

- Complaint, 2026-09-19, r/ClaudeAI (Reddit): “here you go openspec: 4 setup actions, 2 per run, 13 tasks, 4m 26s. spec kit: 9 setup, 4 per run, 24 tasks, 9m 40s. bmad: 10 setup, 4 per run, no task list at all, 36m 5s. kiro: 0 setup this time since it was already installed, 21 per run plus 84 allow clicks, 29 tasks, 2h 11m, 39 of 50 free credits. all four shipped it, none needed a fix from me, none touched the server. spec kit and kiro added a grip handle nobody asked for, bmad added 3 dev” [source](https://www.reddit.com/r/ClaudeAI/comments/1wkktmh/i_measured_what_four_specdriven_tools_actually/parokx4/)
- Complaint, 2026-09-07, @kirodotdev (X): “someone from @kirodotdev , please fix the ui , and also bring in modes to auto approve , even if its in autopilot , the model(even sol and opus 5) keeps coming up with random most commands and asking permission every single time . <strict_link>” [source](https://twitter.com/1308410318108995585/status/2097051318175289737)
- Complaint, 2026-09-02, r/kiroIDE (Reddit): “for multiple permissions dialog box kiro incorrectly registers accept all as reject. even clicking on green tick gives reject signal to kiro.” [source](https://www.reddit.com/r/kiroIDE/comments/1w5nh3m/bug_report/)

### Amp

- Praise, 2026-09-26, @AmpCode (X): “@phutrong00 @muse @ampcode should be fine. i have a similar setup with grok bot but i just give it access to the cli and let it use it as it sees fit. this though is a nice manual way to control that.” [source](https://twitter.com/394369752/status/2103884392259285009)
- Complaint, 2026-09-26, @AmpCode (X): “@thorstenball @ampcode i have a skill to address pr feedback and the model usually asks me in text “may i continue?” seems like that’s a perfect place to give the user a ui element” [source](https://twitter.com/5444392/status/2103705622650978634)
- Complaint, 2026-09-26, @AmpCode (X): “@thorstenball @ampcode probably! curious that i never see the modal use the choice tool is all” [source](https://twitter.com/5444392/status/2103706972151587097)
