Finding / agent-flywheel

Edited by Michael Ruescher

Vibe mode writes passwordless sudo; safe mode does not revoke it

The active v0.7.0 installer writes /etc/sudoers.d/90-ubuntu-acfs with $TARGET_USER ALL=(ALL) NOPASSWD:ALL in vibe mode, chmods it to 440, and validates the file with visudo. A safe-mode run skips that write. It does not delete the file left by an earlier vibe-mode run or revoke another passwordless-sudo rule; the tagged Hetzner cloud-init example itself creates one. Channel: tagged-release intake baseline. Operator consequence: safe mode is not a sudo-remediation step. On a fresh host with no other NOPASSWD rule it does not create the ACFS rule, but an operator changing modes must inspect and remove prior/provider rules separately. This was an intake baseline, not a July 1-2 product change.

Receipt

Finding metadata

Run: 2026-07-02-weekly-digest-2026-07-01_2026-07-02-frontier-v0

Finding ID: 2026-07-02-agent-flywheel-passwordless-sudo-vibe-default

Profile citations

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact