deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

A dev.to post argues disposable containers are the real fix for AI agent approval fatigue

A dev.to post argues that constant approval prompts train developers to stop reading what they approve — and that running agents in disposable containers is the safer default.

A dev.to post argues disposable containers are the real fix for AI agent approval fatigue

The approval prompt that protects nothing

Anyone who has run a coding agent knows the rhythm, a recent dev.to post observes: the agent drafts a command, halts, and waits for a click. By lunchtime a developer has approved dozens of commands and long since stopped reading them. At that point, the post argues, the safety mechanism protects no one — it has become a ritual that trains you to say yes.

The prompt exists because the agent executes real code on the machine holding your SSH keys, cloud credentials and months of uncommitted work. On that hardware, "do you trust this command?" is worth asking. Inside a container you can destroy with one click, the post contends, the question barely matters.

What Codex's help text actually says

The post walks through the three approval modes OpenAI's Codex exposes via codex --help:

  • --ask-for-approval never — the agent never pauses for permission.
  • --approve-for-me — a second model reviews each command instead of you.
  • --dangerously-bypass-approvals-and-sandbox — disables both prompts and the sandbox.

The third flag's own help text calls it extremely dangerous and says it is meant only for environments that are already sandboxed outside the tool. The post's reading is that this is not a warning to never touch the flag but a statement of its precondition: a laptop is not such an environment, while a disposable container is. The same switch means something entirely different depending on which machine it runs on.

Why half-measures on a laptop keep failing

Developers who try to quiet the prompts hit recurring walls, according to the post, which cites a string of Codex GitHub issues: granted folders that still are not trusted even with bypass flags enabled, session-level approvals forgotten on restart, Full Access mode that keeps prompting anyway, sandbox mode that asks about routine commands, and MCP tools requesting permission on every call. The most prominent thread, the post notes, describes the tool as unusable on Windows because of a permission prompt on every shell command, while a separate issue about token waste in approve-replan loops has drawn 630 comments.

The diagnosis: prompts are tedious when they work and broken when you try to switch them off — the predictable result of bolting a security gate onto a machine that was never built as a security boundary.

The middle option bills you by the decision

--approve-for-me routes decisions to a second model — internally the "guardian" reviewer, listed as guardian_approval in the features output — so only unusual commands reach a human. The post calls this a reasonable compromise but is candid about the price: every skipped prompt is another model call. You pay in tokens for not having to look.

Order of operations: blast radius first, freedom second

Once the agent runs in a container, the calculus inverts, the post argues. Asking every time means approving commands that cannot hurt anything. AI review buys protection you mostly no longer need. "Never ask" stops being reckless and becomes the scenario the help text describes.

The sequencing matters: first decide how much damage one bad command can do, then decide how much autonomy to grant. Do it in reverse and the only options left are too noisy or too risky.

The project behind the post

The post is built around TaskHandoff, an Apache-2.0 licensed control plane for running AI and Codex workspaces on your own machines. Every session lives in a managed Linux Docker container that you create, start, stop and delete from one console, according to the post. It offers workspaces you own, with snapshot, restore and rebuild; templates that preserve a working toolchain across projects; one console driving several machines, so heavy jobs run on a Linux box while you steer from a laptop; and a live session view over WebSocket. It ships as a desktop app and as a server installable as a systemd service on Debian and Ubuntu, with English and Chinese interfaces.

The caveat the post itself raises

Giving the agent full access inside the container means the container is now the thing keeping you safe, so it must be genuinely disposable. The post's advice: never mount your only copy of your credentials into it, do not treat it as a password vault, and if a task truly needs the host machine or Windows-only tools, leave the prompts on.

Why it matters

Approval fatigue is an under-discussed failure mode of agentic coding: the control meant to keep humans in the loop decays into muscle memory. The post's core framing — shrink the blast radius first, then grant autonomy — applies to any tool that executes shell commands, not just Codex, and it reframes scary-sounding bypass flags as environment-dependent rather than inherently unsafe. The container does not remove the security decision; it moves it somewhere the decision can actually hold.

  • #ai-agents
  • #codex
  • #docker
  • #security
  • #open-source

Related posts