The agent host as an operating system problem: permission, patching, and detection
The agent host as an operating system problem: permission, patching, and detection
Question and answer, October 5, 2026. An always-on personal coding agent needs enough authority to act on the owner’s projects, and sufficient observability to detect machine changes, without giving every agent-generated executable free access to private data. A good operating record would log the grant, remote exposure, patch level, alert, verified remediation and subsequent service. The October 5 first-person account by Ben Thompson supplies an alert-to-wipe story and a concrete permissions complaint, not logs or a controlled test of agents as security guards.
First-person sequence. Thompson’s dedicated Mac mini runs Claude and Codex, with a persistent Claude Code thread recording ideas and project status. Its scheduled restart of a monitoring tool brought an urgent agent warning about unexpected file changes and passwordless admin capability; he says the agent stopped commands, then—with Thompson deliberately overriding its advice to stop using it—helped locate a four-second compromise interval, inspect the miner, create a watcher and wipe the host. He says macOS’s protected GUI permission prompts routinely forced him to log in with screen sharing, and acknowledges that he had left screen sharing accessible without a VPN and had not installed the relevant OS patch. The direct operational result is an owner-reported detection and rebuild; without host logs, independent forensics, a record of port exposure, or follow-up, this cannot quantify detection sensitivity, causality, or post-wipe resilience.
Verified dates and conditions. Apple’s Tahoe 26.6.1 advisory dates the fix for CVE-2026-65400 to August 6, 2026; Sequoia 15.7.9 and Sonoma 14.8.9 carry the same authenticated screen-sharing issue. The Dutch NCSC advisory was published August 7 and revised August 12 to report multiple actively exploited machines with internet-accessible port 5900, root access and Monero miners. Thompson’s quotation from an August 14 article says ‘last week’ for the patch and Black Hat disclosure. That relative date belongs to August, not to the date of his October 5 essay. NCSC confirms attacks on some exposed machines; it does not independently identify Thompson’s host or the exact entry path. Patch and exposure should not be causally assigned to TCC prompts alone.
What Apple actually announced. Apple’s October 2 Full Disk Access note warns that the grant could expose files, messages, browsing history and correspondents and says additional explicit-user-action controls will be introduced; it specifies neither shipped restrictions nor a new policy for agent-created programs. Current Apple sandbox documentation says applications cannot programmatically give themselves Full Disk Access; users grant it in Settings, while a separate Desktop permission is app-scoped. Thompson argues for grants to a supervising agent rather than each generated program and reports that agents cannot see protected GUI approval prompts. This would improve unattended operation in his case, but broad inherited authority poses a larger blast radius if the agent executes untrusted content. Apple’s privacy rationale includes the third parties in correspondence; this is a real disagreement about the consent subject, not proof Apple has already blocked all agents.
Update-setting cross-check. Apple’s Software Update settings guide lists separate options to ‘Install macOS updates’ and to install ‘Security Responses and system files’. The latter is not a promise to install every security-fixing point release. Thompson admits misreading his configuration; his precise setting and current version were not independently shown. Do not repeat the general claim that Apple failed to deliver a promised automatic security patch; do distinguish background content from OS updates.
Connection and still missing. A persistent agent interface carries ongoing machine security labor as well as runtime spend; private/work authority boundaries make a blanket grant harder for teams; decision memory and real-world checks should include known permissions denial and patch status before automation is labeled healthy. The next comparable account needs a before/after permission and network-exposure ledger, active operator minutes, and a recovered or interrupted actual task. Fowler’s notation discussion is a separate conceptual thread, not evidence of this breach.