Finding / agent-flywheel

Edited by Michael Ruescher

Agent Flywheel's dangerous shortcuts are installed in both modes

In v0.7.0, ACFS installs and sources one shared zsh configuration in both vibe and safe modes. That file defines cc with --dangerously-skip-permissions, cod with --dangerously-bypass-approvals-and-sandbox, and agy/gmi through the agy-locked wrapper without checking the selected mode. The README frames those flags as vibe-mode behavior and says safe mode keeps standard confirmations. Channel: tagged-release intake baseline. Operator consequence: even on a fresh host where safe mode skips ACFS's passwordless-sudo write, it does not remove the dangerous agent shortcuts in this tag. Safe mode also does not revoke prior or provider-supplied passwordless sudo. This was observed during the July 2 intake, not introduced inside the July 1-2 window.

Receipt

Finding metadata

Run: 2026-07-02-weekly-digest-2026-07-01_2026-07-02-frontier-v0

Finding ID: 2026-07-02-agent-flywheel-vibe-mode-dangerous-agent-aliases

Profile citations

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact