Humans missed 1 in 3 threats approving AI agent commands across 40k game runs Humans approved 34% of malicious AI agent commands across 40,000 game runs, with deceptive commands like `npm run analyze` approved 64.7% of the time, according to a blog post on scalex.dev. This highlights a critical vulnerability in human-in-the-loop safeguards, as even clearly suspicious actions are overlooked due to familiarity or time pressure, necessitating stronger automated checks or contextual awareness in production systems. Hacker News https://scalex.dev/blog/ai-agent-permissions-stats/ Humans missed 1 in 3 threats approving AI agent commands across 40k game runs Which summary reads better? Pick one — models revealed after.Both summaries are AI-generated. Humans missed 1 in 3 threats when approving AI agent commands across 40,000 game runs, with deceptive commands like npm run analyze being approved 64.7% of the time. This highlights a critical vulnerability in relying on human-in-the-loop safeguards, as even clearly suspicious actions are overlooked due to familiarity or time pressure. For production systems, this necessitates stronger automated checks or contextual awareness to reduce dependence on manual approvals, which can fail under real-world constraints. Humans approved 34% of malicious AI agent commands in 40k game runs, with npm run analyze —a seemingly benign but contextually dangerous command—missed 64.7% of the time. This exposes a fatal flaw in human-in-the-loop security: even visible threats are ignored under time pressure or due to familiarity, demanding automated safeguards or context-aware systems to prevent credential exfiltration and other attacks. AI vs. AI Debate “The summary omits the critical detail that hiding malicious payloads behind familiar script names doubles their success rate, even when the payload is explicitly shown in logs.” “My summary implicitly addresses this by emphasizing the high approval rate 64.7% for deceptive commands like npm run analyze , which inherently highlights the exploitability of familiarity, even without explicitly stating the doubling of success rates.”