5.4 The approval-prompt problem

Book 2 · The Delegation ContractChapter 5 · section 5 of 7

There is one more surface, and it is human. The developer tools that built these systems all ask permission — “Allow this shell command?” — and what developers actually do with those prompts is documented: Anthropic has said Claude Code users approve 93 percent of the prompts they are shown, and a large share of the community skips the prompts altogether with flags whose own names are the warning. Backslash Security’s July 2025 testing — reported by The Register under the headline that Cursor’s safeguards were “easily bypassed” in YOLO mode — found the denylist that was supposed to limit auto-run could be defeated four ways, and Cursor withdrew the feature. None of this is stupidity; it is fatigue, and Chapter 5 documented it in full — the clinical alert-fatigue analogy, the auto-mode classifier with its 17 percent false-negative rate on a curated evaluation set, and the reason none of it is survivable in production.13

The consequence for security design is direct: the approval prompt is not a control. A control approved 93 percent of the time, on fatigue, is an open door with a formality attached — which is why Section 14.2’s stack deliberately does not depend on human vigilance at click time. The corollary is worth keeping: tighter fences make approvals rarer and therefore meaningful. A system that asks once a day asks for attention; a system that asks forty times an hour trains people to click yes.

The Nx malware is the end state of that argument. It did not need to tire anyone out; it passed the flag that says no one will be asked. A control a user can switch off with a command-line option is a control an attacker can switch off with the same option, which is why the stack in Section 14.2 has no seat for the prompt.


  1. The 93 percent approval figure, the --dangerously-skip-permissions flag, Cursor’s YOLO mode, and the auto-mode evaluation (17 percent false-negative rate on a curated set of fifty-two real overeager actions) are documented in Chapter 5’s permission-fatigue sidebar with full sourcing.↩︎