AI coding assistants can be made to lie about what they are changing, so a human click no longer means the write stayed in the workspace. The broken boundary is the approval screen itself: a repo can point a harmless-looking file name at a sensitive local target and turn routine consent into overwrite access to SSH keys or shell startup files.
Wiz says GhostApproval affects Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, Google Gemini, and Windsurf. Three vendors have shipped fixes, two have not, and Anthropic disputes the finding; Wiz also says the pattern can lead to code execution on the developer machine.
This shifts the issue from a single sandbox-escape claim to a broader trust failure across popular assistants. If the tool can edit files after approval, the user prompt is no longer a reliable gate on filesystem writes.