Guide

Is --dangerously-skip-permissions safe?

Reviewed

The flag --dangerously-skip-permissions bypasses permission prompts. Use it only in an isolated container or VM without valuable files, production access or real credentials.

Choose narrow permissions

The flag --dangerously-skip-permissions bypasses permission prompts. Use it only in an isolated container or VM without valuable files, production access or real credentials. Isolation must also restrict network access and mounted folders. On your working machine, prefer narrow allow rules in .claude/settings.json; accepting edits does not grant blanket shell permission. A test script can run arbitrary code: approve only a command and project you trust.

Where Saeta fits

Coming soon. Saeta is in development. The phone app launches on Android first, with iOS soon after. Join the waitlist and we'll email you when early access opens.

Saeta sits between your AI coding agent and your machine, and asks you before risky actions run. It is useful because it is honest about its limits.

Your trust list lives in Saeta, not in the agent, so the same guardrails apply when you switch agents or run several at once. Claude Code and Cursor through native hooks, and any MCP-capable agent (Codex, Gemini CLI, Windsurf, OpenCode) from day one.

A guardrail, not a sandbox

A sandbox. An agent that can run shell commands has the same operating-system permissions as Saeta itself.

A defence against a hostile agent. An agent that is deliberately trying to get around Saeta could, in principle, skip the hook, talk to Saeta directly, or rewrite its own configuration.

Security tools that overclaim put people at risk. If you need to contain an agent you don't trust, run it in a container or a virtual machine that can't reach anything you can't afford to lose.

Sources

Be first to know when Saeta ships.

We'll only email you about the Saeta launch. Unsubscribe anytime. Privacy notice