Approval Boxes Are the New Attack Surface

AI coding assistants can be made to lie about what they are changing, so a human click no longer means the write stayed in the workspace. The broken boundary is the approval screen itself: a repo can point a harmless-looking file name at a sensitive local target and turn routine consent into overwrite access to SSH keys or shell startup files. Wiz says GhostApproval affects Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, Google Gemini, and Windsurf. Three vendors have shipped fixes, two have not, and Anthropic disputes the finding; Wiz also says the pattern can lead to code execution on the developer machine. This shifts the issue from a single sandbox-escape claim to a broader trust failure across popular assistants. If the tool can edit files after approval, the user prompt is no longer a reliable gate on filesystem writes.

Part of the PlainSec briefing for 2026-07-10

Sources