Virgil
Platform engineer. Writing about systems, cloud, AI and automation.
If you use Claude Code for anything beyond simple edits, you’ve run into this: you’re mid-task, the agent needs to search the web or read a file, and it stops to ask permission. This is disruptive to the flow. The naive fix is to just trust the agent more — expand the allow list, enable auto mode and move on. But that’s not a viable long-term solution. An agent that self-certifies its own intent is exploitable. If a model can decide that fetching a URL is “just reading,” it can be manipulated into deciding that almost anything is. ...