Comment by coderbants
6 hours ago
Terminal is a significant risk though and I’d still really like to see macOS improve the APIs around filesystem access.
Granting terminal full disk access grants arbitrary scripts full disk access. There’s a lot you can do with ACLs and the permissions system, but it’s not reflected in the UI for settings.
Then there’s allowing access to documents, downloads, desktop, external disks. This should really allow the user to select a path or paths for applications, because these options are way too broad (especially external disks).
This is why I use Terminal as my primary terminal, and iTerm as my AI terminal. iTerm gets no permissions, I move specific things to Terminal to do it. Plus I can then style them to optimize for the different usages. And iTerm has better harness hooks anyway.
I would still like to see not only more granular permissions, but single use permissions. Once I grant iTerm access to Documents for whatever reason, it always has such permission. I would be nice to limit that to a single use, or a single harness session.
> Granting terminal full disk access grants arbitrary scripts full disk access.
Indeed, I run all dev tools including coding agents inside sandbox now
https://github.com/ashishb/amazing-sandbox