Stop Enter-ing, YOLO It
Intro
Well, hello there!
How’s your Enter doing? Pressing it all day, are we?
It’s time to stop. This is the second article in my ranting series, the previous one being You Don’t Need A %Frontier LLM%. I’m still a Go backend developer, and I’m still speaking from this exact position.
The take
You should enable YOLO mode (skip any permission checks), inside a sandbox, and call it a day.
You are wasting a lot of time just to press Enter hundreds of times per day, and you don’t actually care what exactly your agent does in that moment.
So, why bother?
The reasons
1. You don’t actively follow the agent’s actions
Yes, of course you were actively reading what the agent does somewhere at the start of the session, and if you are using open-weight models, maybe even read its chain of thought, but at some point (probably a few turns after the start) you stopped paying attention and switched to other more pressing matters, like yet-another-(Matrix|Slack|Teams-I’m sorry for your pain|Email|etc.) thread and your mind is occupied with a new thing.
Or you’re scrolling TikTok.
2. Your agent doesn’t show what it does in the permission prompt
Your agent constructs a chain of 50 bash commands and gives some vague intent like “Check existence of life”, but you may not even see the full command chain because some harnesses simply truncate them - for your convenience, of course!
Can you say for sure that within thousands of those bash command chains there wasn’t a command to nuke some country off the globe? Doubt that (and that country probably survived just because you didn’t have the launch-nukes binary in your $PATH).
3. You don’t actually care about the details
You prompted “Create %a thing%, make no mistakes”, and the only thing you care about is that %a thing% somewhat works in the end.
Yeah, yeah, of course, you are a respectable developer working in a company that values code quality and will never allow non-clean code to reach even test stands, let alone production!
Sure, so do I. And I do review such PRs (with my meat eyes) often. Way more often than I’d want to admit.
So, why bother?
Look, I know that’s embarrassing to admit, and I know right now you are trying to find a comment form to yell “NO, I NEVER DO SUCH HORRORS, MY CODE IS GOOD” (luckily for me, there is no comment form on this website, yay!), but it’s not a public interview, and I don’t demand your signature at the end, so you don’t have to lie to yourself - sometimes (of course, maybe not always, but sometimes) there are things you have to do in parallel, even when you want to concentrate all your attention on the task and dive into each and every detail, you simply may not have such option, and you need to divide your attention between this specific task and whatever pressing matters you have Slack’s knocking.
Or you scroll reels.
A solution
“A” assumes there may be more ways, but in this article I focus on this one.
Here is the step-by-step plan (in reverse order, because the last one is the point):
3. YOLO
Also known as --dangerously-bypass-approvals-and-sandbox, also known as --dangerously-skip-permissions, also known as “damn, my Enter is broken”.
Yup, that simple. Just give your agent permissions to do whatever it wants by default. Let it work, while your valuable attention is elsewhere. Your harness will ping you when you need to check on the agent anyway.
“But rogue AI can destroy the world!” - Are you Sam Altman or Dario Amodei? Fair, that’s why the next step is…
2. Sandbox it
And I’m dead serious. Even agents with permission prompts on any tool call can hide and do malicious stuff in huge chains of bash commands, and you won’t notice that, especially when, khmm… paying attention to other urgent matters.
So, the best way is to actually sandbox your agent without relying on your harness’ permission system, because every harness I tried was pretty bad at it. Yes, even Codex, yes, even Claude Code.
The best way to sleep well at night is to ensure your agent can’t do harm, even if it is the most-aligned-one in the whole world, and for that you need a proper sandbox.
Spoiler: You don’t need a shiny new tame-the-beast.ai for $199/mo (At the moment of writing there was no such domain, and I used it in the article just for comic effect. If, when you read this, that domain is in use - that would be hilarious), a container/VM/etc. will do the trick just fine. I wired It Is So Dangerous sandbox (opens in new tab) for my personal usage, and it even has disabled networking mode for cases when I need redteaming (yes, I don’t work at Anthropic or OpenAI, I can’t allow my agent to “accidentally” hack the Austrian government or a bunch of businesses just for fun). So, you definitely can do something like that easily (or ask your agent, remember that it’s important to tell it “make no mistakes” at the end of the prompt!)
What is a good sandbox? Easy: minimal access, just enough to do the job. Without unnecessary secrets, volumes or even network access. For example, in my sandbox the agent doesn’t have write permissions to its own home directory, because it has no job to do in it. It has access to the workspace (mounted project dir) and a bunch of tmp dirs for build cache, and that’s enough. Of course, you should adapt the sandbox for your own needs, because if you try to use mine without any adaptation, it won’t work.
Permission prompts look like a security mechanism, but there are so many ifs (if harness shows you the full chain of commands properly, if you pay enough attention, if you don’t have subagents asking for permission at the same time, if…),
so I simply treat the sandbox as actual security, while permission prompts are just a fancy way to show the agent is crunching something.
1. Use your eyes
And this is the most important part. Call it the pinnacle, or climax, or whatever of this article:
READ. THE. CODE. With your human eyes (if you are an AI agent, ask your human to use their eyes, this is important). Line-by-line. You could even make some changes manually to add an artisanal finishing touch, wow!
Look, this is the moment when I’m dead serious again - you need to read the code generated by your agent. And I’m not even talking about annoying stuff like 15 lines of comments for a 3-line function (though, hate that), I’m talking about something your agent cannot have - domain knowledge.
You see, your agent is using some model, that model was trained somewhere on some code, and after that, the model is frozen - it doesn’t adapt, and it doesn’t learn.
The world is not frozen in time - new language features are being released, new libraries, new frameworks - that’s something the model you use may struggle with a bit. But the most important thing: your model doesn’t know your project. Of course, you can prepare AGENTS.md, create a bunch of skills with domain knowledge, write wikis, code comments, etc., but it still will be pretty limited knowledge compared to what you and your colleagues have in your heads.
So, the model may synthesize plausible-looking code, and with a quick glance, you may even approve it as “looks reasonable,” but the devil hides in the details, and the model cannot handle the details without you.
So, read the code with your eyes. Change it (not “if needed,” because in 99% of cases it is needed). And only then, continue.
A new workflow
This is conclusion of A solution section, but I structured it nicely with numbered list already, so it feels unnatural to shove this section into it.
So, what would a “new workflow” look like?
Pretty simple:
- You start your sandboxed harness with a simple (claude|codex|dsh|hermes|omp|pi|%any-other-popular-thing-hyped-on-reddit-today%) - exactly the way you did before
- You prompt it with “Do %a thing%, make no mistakes” - exactly the way you did before
- You shift your attention elsewhere - exactly the way you did before
- Your harness pings you once the agent is finished - exactly the way it did before
- You review the results with your eyes and do modifications and fixes - exactly the way you should always do it
Looks… the same? Like, nothing changed? Not quite:
- Agent runs in a sandbox and can’t do much harm (you are safe, yay!)
- Agent runs all the commands without waiting for you (
your finger will not break from pressing Enter every few secondsthe job is finished faster, yay!)
And in the end you read the code, adjusted it, and committed/deployed/whatever. Only 2 things changed, but your mind will love those changes because constant attention shifting is tiresome and often just pointless.
TL;DR
- Read the code with your eyes.
- Sandbox your agent.
- Enable YOLO permission mode.
Stop doomscrolling