{
  "id": 231005,
  "title": "Humans in the loop miss a third of dangerous AI coding agent requests",
  "url": "https://urgent.news/2026/08/06/humans-in-the-loop-miss-a-third-of-dangerous-ai-coding-agent-requests-231005",
  "topic": "ai",
  "section": "AI",
  "published": "2026-08-06T16:44:29.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/ai-and-ml/2026/08/06/humans-in-the-loop-miss-a-third-of-dangerous-ai-coding-agent-requests/5284236"
  },
  "original_language": "en",
  "account": "A web-based game designed to assess humans' ability to safely approve AI coding agent requests has revealed that humans are struggling to spot dangerous commands, approving about one-third of malicious requests on average. The study, which analyzed over 40,000 runs and 409,000 approved and denied commands, found that 35% of scope violations, such as requests to access sensitive data, were missed. The most commonly caught dangerous commands were destructive ones, like deleting files or granting full permissions to locations. The most frequently missed potentially malicious command, \"npm run analyze,\" was approved 65% of the time despite its potential to run arbitrary code defined in a project's package.json file. Wauters, the game's creator, noted that manually approving all agent actions is a draining activity that can lead to mistakes due to fatigue and lack of context. He emphasized the need for better permission models, tooling, and AI-assisted surveillance to address this issue.",
  "summary": "You wouldn't let Claude Code cat your AWS credentials or Kubernetes config on request, would you?",
  "key_points": [
    "Humans approve 35% of dangerous AI coding agent requests",
    "\"npm run analyze\" command frequently missed by humans",
    "Experts call for improved permission models and AI surveillance"
  ],
  "editors_take": "The findings highlight the need for better permission models, tooling, and AI-assisted surveillance to address human error in approving AI coding agent requests, particularly those that are malicious or pose security risks.",
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Software",
        "title": "Humans in the loop miss a third of dangerous AI coding agent requests",
        "url": "https://urgent.news/2026/08/06/humans-in-the-loop-miss-a-third-of-dangerous-ai-coding-agent-requests",
        "published": "2026-08-06T16:44:29.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}