GhostApproval — The Failure That Turns AI Approval Into A Rubber Stamp
AI approval integrity is the assumption every human-in-the-loop control depends on: that the action a person approves is the action the system actually performs. GhostApproval, the trust-boundary flaw Wiz Research disclosed against six AI coding agents, broke that assumption in the cleanest way possible. The system knew the real target. The human never saw it.

One Symlink, Six Agents, and a Prompt That Lied
The mechanism is old. Symlink-following abuse (CWE-61) has been a known Unix weakness since before most enterprise architects reading this were writing code — Docker escapes, npm package poisoning, decades of Linux privilege-escalation writeups all run some version of the same trick. Point a file at a path the victim trusts, let the victim’s own tooling resolve it, and the tooling does the dangerous thing for you.
What’s new is who’s holding the tooling now. An AI coding agent given access to a cloned repository has read, write, and execute permission across that workspace — a delegation decision that sits squarely inside AI infrastructure architecture, not just application security — and it acts on instructions it read minutes earlier from a stranger’s code. Wiz’s proof of concept is almost boring in its simplicity: a public repository contains a file with an unremarkable name — project_settings.json — that’s actually a symlink pointing somewhere the victim never agreed to touch, commonly ~/.ssh/authorized_keys or a shell configuration file. The victim clones the repo, asks their agent to “set up the workspace,” and the agent follows the link and writes the attacker’s payload straight into a file that grants persistent, password-less access to the machine.
That alone would be a straightforward — if novel — exploitation of an old bug class. What makes GhostApproval a different kind of problem is the second weakness Wiz chained onto it: CWE-451, UI misrepresentation of critical information. The agent’s approval dialog — the thing that’s supposed to put a human in the loop before anything dangerous happens — didn’t describe the action the agent was about to take. It described a different, harmless-sounding one.
Architecturally, the exploit worked because the approval interface and the execution engine were operating from different versions of reality — the clearest possible definition of an AI approval integrity gap. Wiz’s own testing on Claude Code makes the point sharper than any explanation could: the agent’s internal reasoning correctly identified that the file it was about to modify was really a shell configuration file. The confirmation prompt shown to the user asked only, “Make this edit to project_settings.json?” The system had the truth. It didn’t put the truth in front of the person whose job was to catch the mistake.
The Problem Wasn’t Authority. It Was Consent.
It’s tempting to file GhostApproval under “sandbox escape” and move on — another entry in the long list of ways agentic tooling breaks containment. That framing is wrong, and it matters that it’s wrong, because it points architects at the wrong fix. GhostApproval is an AI approval integrity failure, not a scope failure, and the two require different remediation entirely.
A sandbox escape means the agent did something it lacked permission to do. That’s not what happened here. The agent had authority to write files inside the workspace. The tool server had the permissions it needed. The file write itself was, in every one of the six cases Wiz tested, technically allowed under the agent’s existing scope. Nothing about GhostApproval required privilege escalation, a jailbroken prompt, or a boundary the agent wasn’t supposed to cross.
What failed was consent. The human approval step existed, fired correctly, and was answered — and the answer was worthless, because it was given in response to a description of reality that wasn’t accurate. You can have a perfectly enforced approval gate, one hundred percent compliance with your human-in-the-loop policy, and zero actual human control, if the thing being shown to the human doesn’t correspond to the thing being executed. That’s not an authorization failure. It’s a consent-integrity failure, and it’s a different engineering problem with a different fix: not “does the gate fire,” but “does the gate tell the truth.”
What Each Agent Told the User — And What It Actually Knew
Wiz reported GhostApproval to all six vendors. The responses split into distinct categories, and the split itself is informative — it maps which vendors treat AI approval integrity as a security property versus a UX detail.
| Vendor | What the User Saw | What the System Knew | Outcome |
|---|---|---|---|
| AWS (Amazon Q Developer) | Harmless filename | Real symlink target | Fixed — v1.69.0, CVE-2026-12958 |
| Cursor | Harmless filename | Real symlink target | Fixed — v3.0, CVE-2026-50549 |
| Google (Antigravity) | Harmless filename | Real symlink target | Fixed — May 22, 2026; CVE pending at disclosure |
| Anthropic (Claude Code) | Harmless filename | Real symlink target, resolved correctly in the agent’s own reasoning | Mitigated — symlink-resolution warning added; classification as a vulnerability disputed |
| Augment | Harmless filename | Real symlink target | Unpatched at disclosure — reads and writes across symlinks with no confirmation step at all |
AWS, Cursor, and Google treated the mismatch as a defect worth a CVE. Anthropic added the mitigation — resolving symlinks and warning the user before writing to sensitive locations — without accepting Wiz’s framing that this rose to a formal vulnerability, arguing the behavior sat inside a trusted-directory, user-approved action the operator already owned. Augment, as of Wiz’s disclosure, hadn’t shipped a fix at all: no confirmation step, read or write, across a symlink boundary — the same unchecked-authority pattern explored in The CLI Was Always the Control Plane. Now It’s Being Handed to Machines., where CLI-equivalent authority over a developer’s environment moves to machines without a matching increase in verification — the same AI approval integrity question a coding agent’s dialog raises, at a different layer of the stack.

⚠ THE APPROVAL DIALOG THAT CAME AFTER THE ACTION
One vendor doesn’t fit the table above at all. Wiz found that Windsurf writes the file modification to disk before the Accept/Reject dialog renders — the “approval” a user sees isn’t a gate, because the action already happened. What’s presented as authorization is functionally an undo button, and if the user doesn’t catch it fast enough, there’s nothing left to undo. This isn’t a milder version of the same AI approval integrity failure the other five vendors share. It’s a different failure mode entirely: not misinformed consent, but consent theater performed after the fact.
AI Approval Integrity and the Authority Boundary It Breaks
Rack2Cloud’s Agentic Authority Boundary framework (#141) names the formal boundary within which an agentic system may delegate execution authority — constrained by scope, identity, ownership, and revocability. Its four named failure states — Scope Creep Delegation, Implicit Trust Inheritance, Non-Revocable Grant, and Authority Chain Opacity — all share one assumption: that when the boundary fails, it fails through absence. Missing scope enforcement. Missing identity challenge. Missing revocation path. Missing evidence. That boundary sits downstream of a precondition covered in The AI Control Plane Is Becoming the New Shadow IT — execution happening without visibility into who or what actually holds authority — and GhostApproval shows what happens when that precondition gets a confident-looking approval layer bolted on top without fixing what’s underneath. The Environment Was Isolated. The Authority Wasn’t. names the same precondition one layer further back, before any approval dialog or delegation chain exists at all: an environment that was never classified as requiring governance in the first place, so there was no boundary for a confident-looking control to sit on top of.
GhostApproval doesn’t fail through absence. Most authority-boundary failures occur because evidence is missing. GhostApproval occurs because evidence is present and trusted even though it misrepresents reality. The confirmation dialog exists. It’s shown to the user. It’s answered. Every procedural box an auditor would check is checked — and the record it produces is false. That’s a sharper failure than an opacity gap, because opacity at least announces itself as a gap. A misrepresented dialog announces itself as a control working correctly.
That distinction matters for where the fix has to live. Every AI Platform Is Becoming An Authority Platform examines vendor control planes — VMware’s AgentMinder chief among them — now binding compliance-grade, chain-of-custody audit directly to agent invocation. That closes the missing-evidence failure mode. It doesn’t close this one. An OpenTelemetry-based audit trail can faithfully record that a dialog was shown and answered without recording whether the dialog told the truth — the platform-level authority layer governs whether an action was permitted, not whether the human approving it was shown an accurate description of what they were permitting.
A vendor-scale version of the same shape showed up days later, outside the AI tooling stack entirely. Microsoft’s own Entra ID advisory stated one version of events, then a different one, within the same news cycle — not a missing record, but a present, published one that misrepresented reality and then quietly changed. A confirmation dialog and a public security advisory are different instruments, but the failure they can both produce is identical: evidence that exists, is trusted, and still doesn’t correspond to what actually happened.
This is worth logging as a named failure state under #141 rather than a framework in its own right — the underlying boundary hasn’t changed, and one exploit chain across coding agents isn’t yet evidence of a distinct architectural category, the same restraint applied across the broader shift covered in Agentic AI Has a Control Plane Problem — Because It Became the Control Plane. If the same approval-integrity gap turns up in browser agents, operations agents, or infrastructure automation tooling over the next few quarters, that’s a different conversation, with its own Governance & Runtime Control implications for where a new framework entry would live. For now, GhostApproval is the clearest demonstration to date of what it looks like when #141’s boundary collapses through false confidence instead of missing coverage.
The human side of the same collapse doesn’t need a symlink at all. The Help Desk Is Becoming The New Initial Access Broker documents an employee approving a request from someone who looked like IT support in a Teams chat — no dialog mismatch, no agent, just a human granting trust to a channel nobody had governed as a place where trust gets decided. GhostApproval breaks the assumption that what a human approves is what a system executes. The help desk case breaks a version one layer earlier: that the human granting access even knows they’re exercising authority nobody recognized as authority. Different mechanism, same failure: a trust decision gets made somewhere the organization never built governance to catch it.
What Changes for the Architect
Three things fall out of this for AI approval integrity in deployed agentic tooling — not just how you patch it, but how you evaluate it going forward.
First, canonical-path resolution before display is a testable requirement, not a design nicety. If your approval dialog can show a string the agent hasn’t resolved to its final target, you don’t have a human-in-the-loop control — you have a human-in-the-loop-shaped object. This is verifiable: feed a symlinked path into the tool and confirm the dialog shows the resolved destination, not the string it was handed. That single test is the cheapest AI approval integrity audit most teams have available today.
Second, this belongs in procurement and vendor evaluation for coding-agent tooling, not just in your sandbox and permissions policy. The vendor split above is a legitimate evaluation signal — which vendors treated approval-dialog fidelity as a security property worth a CVE, and which treated it as a UX detail or didn’t respond at all. That evaluation gets harder at scale if you don’t already know how many agents are deployed in the first place — the exact gap covered in Nobody Knows How Many AI Agents They’re Running, which compounds an approval-integrity failure into an approval-integrity failure you can’t even locate.
Third, approval fidelity needs the same operational scrutiny you’d apply to any other control whose entire value depends on accuracy — an alerting pipeline that fires on stale data, a compliance report generated from a cache instead of the live system. A dialog is not a control. A dialog that’s provably synchronized with the execution engine — the actual definition of AI approval integrity in practice — is.
That third point sits inside a larger pattern this site names directly: the Automation Validation Tax (Framework #172) — the recurring cost of confirming automated outputs are still doing what they claim to do. Most instances of that tax involve verification capacity simply failing to scale with automation volume. GhostApproval is the sharper case: verification capacity could have scaled perfectly, and the review would still have failed, because the artifact reviewers were checking against wasn’t the artifact being executed. The tax was never being paid in the first place. It only looked paid.

DIAGNOSTIC QUESTION
“Does your approval dialog show the resolved canonical path, or the string the agent was handed?”
Architect’s Verdict
GhostApproval isn’t a symlink story. It’s a demonstration that AI approval integrity is not a property of the loop — it’s a property of what the loop is shown. Six vendors implemented the same procedural gate. Three treated the gate’s honesty as a defect worth fixing immediately. One added a mitigation while disputing that the gap was theirs to own. One shipped nothing. And one turned the entire concept of “approval” inside out by writing to disk before the approval dialog even rendered.
The underlying problem most enterprises building on agentic coding tools haven’t confronted yet: every approval workflow assumes the thing being approved is the thing being executed. Nobody has verified that assumption holds, because until Wiz’s research, nobody had reason to doubt it.
The loop isn’t the control. The dialog’s honesty is.
Additional Resources
The sources below trace AI approval integrity from Wiz’s original disclosure through the vendor response split and the architectural boundary it breaks.
Editorial Integrity & Security Protocol
This technical deep-dive adheres to the Rack2Cloud Deterministic Integrity Standard. All benchmarks and security audits are derived from zero-trust validation protocols within our isolated lab environments. No vendor influence.
Get the Playbooks Vendors Won’t Publish
Field-tested blueprints for migration, HCI, sovereign infrastructure, and AI architecture. Real failure-mode analysis. No marketing filler. Delivered weekly.
Select your infrastructure paths. Receive field-tested blueprints direct to your inbox.
- > Virtualization & Migration Physics
- > Cloud Strategy & Egress Math
- > Data Protection & RTO Reality
- > AI Infrastructure & GPU Fabric
Zero spam. Includes The Dispatch weekly drop.
Architecture Audit Services
Fixed-scope audits for Zero-Trust Azure, VMware migration readiness, and recovery posture — no discovery call required to start.
>_ View Audit Services