Evidence record / paperclip

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.

2026-09-21-paperclip-v2026-831-0-paperclip-stopped-setting-the-wrapped-grok-cli-s-permission-mode-to-dontask

v2026.831.0: Paperclip stopped setting the wrapped Grok CLI’s permission mode to dontAsk. The Grok adapter passes no --permission-mode flag unless configured; before, the control plane injected dontAsk into the wrapped harness by default. --always-approve remains the documented unattended policy.

Channel: tagged-release. Half: defect (closed). Date: 2026-09-02.

Operator consequence: This answers part of the layering question for this pair: before 831.0, Paperclip overrode the wrapped Grok CLI’s own permission default toward permissive without the operator choosing it. Now the harness’s own default governs unless the operator sets a mode. Unattended Grok agents that relied on the implicit dontAsk may now stall on prompts; set --always-approve deliberately if that is what you want.

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-paperclip-v2026-831-0-paperclip-stopped-setting-the-wrapped-grok-cli-s-permission-mode-to-dontask

Profile citations

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact