I use `--dangerously-skip-permissions` and have yet to have it wipe my drive :shrug:. I don't know how I'm supposed to be running dozens of parallel agents each with their own sub-agents while trying to approve commands from each of them, it's just won't scale to the amount of work I need to get done.
Why not let it delete stuff in the current working folder and in tmp, but give it read-only access elsewhere?
The permissions system seems to be mostly finegrained to help you from problems that backups and sandboxes already solve.
The more dangerous activities I find are sending messages to the outside world: I can't undo a dumb slack message to my boss.