Approval Laundering: Systematizing Approval--Execution Binding Failures in AI Coding-Agent Harnesses
Modern AI coding-agent harnesses (Claude Code, Codex CLI, Cursor) rest their security boundary on a largely unexamined assumption: that the action A a human approves is the same action A'the harness executes, where A is fixed by a stated policy for what a scope grant or session-scoped approval authorizes. We show this...