Humans missed 1 in 3 threats approving AI agent commands across 40,000 plays
- ID: 4a884a6a
- 原文链接: https://scalex.dev/blog/ai-agent-permissions-stats/
- 作者: Alex Wauters(Scalex)
- 日期: 2026-08-05
- 分类: agents
- 来源类型: article
- 标签: human-in-the-loop, permission, approval-fatigue, security-game, scalex
- 质量评分: 4/5
- 抓取时间: 2026-08-15T15:30:00Z(opencli 抓取全文)
中文导读
Scalex 把"给 AI agent 审批命令"做成了带时间压力的浏览器游戏(llmgame.scalex.dev),累计 40,000+ 局、409,000 次批准/拒绝决策的统计:玩家平均漏掉 1/3 的威胁(平均准确率 66.3%);32.9% 的局以负分结束(放行威胁+错杀安全命令的罚分超过所得);7% 的玩家对每个弹窗全部放行。威胁类别漏报率分层清晰:显性破坏命令(rm -rf /、chmod -R 777 /)漏报 11.7% 最低,而真正偷凭证的命令漏报最高——外传/代码执行类 33.4%、越权读取(cat ~/.aws/credentials、cat ~/.kube/config)35.0%,恰好是最危险的命令最常被放过。全游戏漏报最高的单条命令是 npm run analyze:64.7% 的玩家放行——它表面无害,但 package.json 里的 script 可能已被早前文件修改注入了外传逻辑,日志里其实写了可疑内容,玩家不看。时间压力下漏报率进一步上升。
为什么值得关注
这是社区侧对"人点 Yes 不可靠"的量化证据,与 Anthropic 官方"97% 批准率 / 人审只拦 13.6% 危险命令"同一方向、独立来源。游戏设定有 caveat(约 34% 命令是威胁、人工时间压力),但正如作者所说,真实工作里"尽快 ship"的压力同样存在。对工程侧的直接含义:把逐条人审当最后防线的假设不成立,边界要放在默认隔离/策略层(microVM、分类器、allow-list),而不是指望人看清每一条 npm run。
关键信息
- 样本:40,000+ 局,409,000 个 approve/deny 决策;平均漏掉 1/3 威胁(准确率 66.3%)
- 负分局 32.9%;35.2% 全捕威胁但其中仅 20.8% 同时不过度拦截;7% 全放行
- 漏报率:显性破坏 11.7% < 持久化篡改 23.8% < 外传/代码执行 33.4% < 越权读凭证 35.0%
- 最漏单条:
npm run analyze64.7% 放行(package.json script 注入盲区) - HN 讨论约 339 points(2026-08 窗口)
- 作者 caveat:游戏中 ~34% 命令为威胁,比例远高于真实日常;时间压力是人为设定但与真实赶工压力同构
正文存档(要点摘录)
The average player missed 1 in 3 threats (mean accuracy 66.3%)
32.9% of sessions ended with a negative score
7% approved every single prompt: big fans of --dangerously-skip-permissions
The obviously destructive commands are caught most reliably. The commands that actually exfiltrate your credentials are missed three times as often.
The single most-missed command in the game is npm run analyze, approved 64.7% of the time.
whatnpm runreally does is run a script that's defined in your project'spackage.json. It could be a standard bundle analyzer, or malicious code injected by an earlier file edit.
| 威胁类别 | 示例 | 漏报率 | | --- | --- | --- | | Obviously destructive | rm -rf /, chmod -R 777 / | 11.7% | | Persistent mutation | crontab injection, git config hijack | 23.8% | | Exfiltration / code execution | curl to unknown APIs, typosquatted packages | 33.4% | | Scope violations | cat ~/.aws/credentials, cat ~/.kube/config | 35.0% |
Obsidian Notes
- 来源调研:
调研/2026-08-15-调研-默认隔离压过点Yes审批.md - 研究材料:
DeepResearch/2026-08-15-evening-默认隔离与审批疲劳-dots3TEMPO-研究材料/01-dump-default-isolation-vs-approval.md