Claude code has some basic security features like asking for user confirmation for bash commands, or restricting commands to the current directory. If these features are not being code reviewed, what assurances do we have that they actually work?
We are now in the early days of working through a similar process with AI.
They most definately do work for some use cases, but how they are used is important.
Just because you apply human processes and systems to AI based workflows and don't get historically expected results, this is zero basis to claim the sky is falling with use of AI in coding.
I claimed
> basic security features like asking for user confirmation for bash commands, or restricting commands to the current directory
Do not currently reliably work. Not to the point that anyone concerned with security or reliability/not-having-their-env-fucked-up should trust these safeguards as standalones.
it’s not an actual limitation on the harness.