1. Human‑in‑the‑loop approval breaks down under fatigue.
"Even with the warning up front, 1 in 3 threats were missed, and the history log above npm run commands seems to be typically ignored." – Wirbelwind
2. User‑prompt security is insufficient; robust sandboxing and capability isolation are needed.
"The best case would be putting an agent in a VM and mounting the working directory there." – danudey
3. Liability is off‑loaded via disclaimers, creating a moral‑crumple‑zone effect.
"The goal of human‑in‑the‑loop is to have someone liable for potential damages, rather than to prevent disasters." – anal_reactor