A transit agency's shared build pipeline began failing when Claude Code runs stalled on permission prompts. An engineer's fix was to add --dangerously-skip-permissions to the pipeline command, and the builds now pass. The security architect is reviewing the change. What is the correct assessment?
Select an answer to reveal the explanation.
Short Explanation
Skipping permissions removes the lock instead of cutting a key. In a shared pipeline, name the tools the job actually needs with --allowedTools and the builds pass with the boundary intact.
Full Explanation
Permission handling in headless automation is a pre-authorization problem, not a prompting problem. A shared build pipeline genuinely cannot answer interactive prompts, but the remedy has to preserve an enumerable set of permitted actions, because the credentials and write access that pipeline holds belong to many teams at once.
Pre-authorizing the specific tools the job needs, through --allowedTools and scoped permission rules, resolves every decision before the run starts. Nothing blocks, and the set of actions the agent may take stays written down, reviewable, and diffable in version control alongside the pipeline definition.
Treating automation as a reason to drop controls inverts the logic, since the absence of a human at the keyboard is exactly why the boundary matters more; claiming the flag merely suppresses prompts for already-allowed tools is factually wrong, because it skips the checks themselves rather than deferring to the allow list; and adding an ask rule for every tool reinstates the prompting that hung the build in the first place.
Exam caveat: --dangerously-skip-permissions is not always wrong, and it is defensible inside a disposable, network-isolated container holding no shared credentials, but an agency-wide pipeline is the opposite of that. Operational check: run the pipeline with the flag removed and only --allowedTools set; if it completes, every tool it truly needs is now enumerated, and any new stall names a capability worth reviewing before it is granted.