Safety · 4 min read ·
Is --dangerously-skip-permissions safe to use?
What --dangerously-skip-permissions, Codex --yolo and Gemini CLI YOLO mode switch off, what to try first, and how to use them without risking your machine.
What does --dangerously-skip-permissions switch off?
Short answer: it is safe only where a mistake cannot reach anything you care about. On the laptop that holds your SSH keys and cloud credentials, it is not.
In Claude Code, the flag is equivalent to --permission-mode bypassPermissions. Anthropic’s permission modes docs say it disables permission prompts and safety checks so tool calls execute immediately. The page then warns: “Only use this mode in isolated environments like containers, VMs, or dev containers without internet access, where Claude Code cannot damage your host system.” It adds that the mode “offers no protection against prompt injection or unintended actions.”
Some things still hold. Deny rules block in every mode, bypass mode included, and removals aimed at a critical path still prompt. On Linux and macOS, Claude Code refuses to start in this mode as root.
Codex has the same switch under a longer name. --dangerously-bypass-approvals-and-sandbox, with the alias --yolo, means no sandbox and no approvals, and its approvals and security docs label it not recommended. Gemini CLI’s --approval-mode yolo auto-approves all tool calls, and --yolo is a deprecated alias for it.
Why does everyone reach for it?
Because asking about everything gets tiring. Anthropic’s best practices page is honest about it: Manual mode is safe but tedious, and after the tenth approval you are clicking through rather than reviewing. A prompt you approve without reading is not a safety check.
The answer to approval fatigue is fewer, better prompts. It is not zero prompts on the machine where your keys live.
What should you try before skipping permissions?
Each tool has middle settings that remove most prompts and keep a boundary.
Claude Code: allow the commands you trust, such as npm run lint or git commit, with /permissions. Turn on the Bash sandbox with /sandbox, which enforces file and network limits at the operating system level so sandboxed commands can run without asking. Or use the modes between Manual and bypass: accept-edits, or auto mode, where a second model reviews actions and blocks the ones that look risky. Anthropic’s tip is to pre-approve trusted tools and let sandboxed commands run, to get fewer prompts without giving up control.
Codex: its default preset lets it read, edit and run commands in the workspace, and asks before it leaves the workspace or needs the network. --ask-for-approval never removes the prompts and keeps whichever sandbox you chose, so the boundary stays.
Gemini CLI: --approval-mode auto_edit approves edit tools automatically and still prompts for the rest. Add --sandbox to keep shell commands inside a sandbox.
If you still go all the way, how do you do it safely?
Follow the vendors’ own advice, and treat these six as a package:
Isolate the agent. Run it in a container, VM or dev container. Anthropic provides a dev container setup that runs Claude Code as a non-root user, and OpenAI’s repository has a secure devcontainer example with firewall-based outbound controls. OpenAI also warns that if you run with full access inside a devcontainer, a malicious project can exfiltrate anything available there, including credentials, so use that pattern only with trusted repositories.
Put nothing valuable inside. No SSH keys, no cloud credentials, no production tokens. If the agent needs access to something, give it a token scoped to one repository or one resource.
Limit the network. Anthropic’s warning names environments without internet access. If the agent needs the web, allow specific hosts only.
Make the work disposable. Use a branch or worktree, commit a checkpoint first, and be ready to throw the result away.
Cap the run. For scripted runs, claude -p accepts --max-turns, which stops the run with an error at the limit, so a loop cannot run forever.
Review the result. Read the diff before anything leaves the container.
What is the safer way to run unattended?
If nobody is there to answer prompts, an allowlist beats bypass. Anthropic’s docs describe a dontAsk mode for locked-down scripts: it allows reads and the tools you pre-approve, and denies anything that would prompt. For example, claude -p "run the test suite" --permission-mode dontAsk --allowedTools "Bash(npm test)" "Read" lets the agent run one command and read files, and nothing else.
Codex’s codex exec starts in a read-only sandbox, and you opt in to edits with --sandbox workspace-write. In both cases you decide what the agent may do before it starts, instead of undoing what it did afterwards.
Why is prompt injection the part to worry about?
Prompt injection is when someone inserts text meant to override an AI assistant’s instructions, as Anthropic’s security docs define it. The text can sit in a web page the agent fetches, an issue it reads or a file in a dependency. With permission checks on, a hostile instruction still has to get past you. In bypass mode, there are no prompts left for it to get past.
That is why “I only run it on my own code” is not enough. The agent also reads things you did not write.
Keep a human in the loop
SwarmPane’s Approvals work on the same principle: nothing edits your files until you approve it. Each request is signed on your computer, so one that changed after you saw it is refused, and Stop ends an approved run and everything it started. Undo for agents can rewind a step byte for byte afterwards.
Code mode runs your CLIs in real terminals, so each CLI’s own permission settings still apply there. Choose them with the advice above.
SwarmPane runs the agent CLIs and accounts you already have. Start with a 7-day trial for $1 and keep the approval step.