4 months ago
a3302cfCodex/Bugbot review (commit e338f16): the sandbox-denial heuristic is necessarily broad (EACCES/EPERM markers), and approveCommand auto-approved everything under YOLO — so an unrelated 'permission denied' failure could silently re-run the command with full-disk access. Lifting the OS sandbox to danger-full-access is a higher trust boundary than running a command, so the 'sandbox_denied' escalation now always prompts, even under YOLO. Normal commands are still auto-approved under YOLO.
Parent0154b9b