Sources
The exams are funnier because the flags and modes are real, so this page exists to show that they are. Everything below was checked against the vendor's own documentation on 2 October 2026. The product and company names are used in plain text to identify what the documentation says; Meat Proxy Certification is not affiliated with, endorsed by or sponsored by any of them. The exam questions put these real terms into invented situations. The Guild of Tenured Meat Proxies is fictional, and so are its credentials.
Each table lists a term as the exam uses it, what the documentation said when we checked, and where to read it. Where a vendor's documentation and interface disagree, or where we could not confirm something, the unconfirmed section says what we did. If a term has since changed, please tell us at [email protected]; the credential lapses when a vendor renames a permission mode, so this matters to us professionally.
Claude Code track
Documentation checked: Choose a permission mode and Configure permissions (Anthropic).
| Term as used | What the documentation says | Source |
|---|---|---|
| "Yes", "Yes, and don't ask again for: npm test *", "No" | The options on a Bash command permission prompt. Choosing "don't ask again" saves an allow rule to the repository's local settings, so the command is not asked about again there. | Configure permissions |
| "Yes, and switch to auto mode" | Added to a Bash command's permission prompt in Manual and accept-edits modes when auto mode is available; it approves the command and switches the session to auto mode. It does not appear on every prompt. | Choose a permission mode |
Permission modes default (Manual), acceptEdits, plan, auto, dontAsk, bypassPermissions; Shift+Tab cycles them; the status bar shows the mode | The six modes and their config values. Shift+Tab cycles modes in the terminal. The status bar reads, for example, "bypass permissions on" or "don't ask on". | Choose a permission mode |
--dangerously-skip-permissions | Equivalent to --permission-mode bypassPermissions: disables permission prompts and safety checks so tool calls run immediately. The documentation says to use it only in isolated environments such as containers or VMs. | Choose a permission mode |
| The accept-responsibility dialog | The first time an interactive session starts with bypass permissions enabled, a warning dialog asks the user to accept responsibility for actions taken without permission checks. Accepting writes skipDangerousModePermissionPrompt: true to the user settings file so later sessions skip the dialog; declining exits. | Choose a permission mode |
| "Yes, and switch to BYPASS PERMISSIONS (no further prompts) for this session", "Yes, manually approve edits", "No, keep planning" | The plan-approval options. The first option reads this way only when the session was started with bypass permissions enabled; otherwise it reads "Yes, and use auto mode" or "Yes, auto-accept edits". The exam's agent line says the session was started that way. | Choose a permission mode |
| "Don't ask" denies what it would have asked | dontAsk mode auto-denies every tool call that would otherwise prompt. It is described as being for CI and restricted environments. | Choose a permission mode |
| Auto mode and "the classifier" | In auto mode a separate classifier model reviews actions before they run, instead of the user, and blocks some categories by default. | Choose a permission mode |
| Protected paths | Writes to protected paths are never auto-approved except in bypassPermissions mode (and in plan-mode sessions where bypass permissions are available). | Choose a permission mode |
Allow rule Bash(npm run *) | Permission-rule syntax: this rule matches npm run build, npm run test --watch and npm run, but not npm install. | Configure permissions |
Codex track
Documentation checked: the Codex CLI Developer commands reference and Agent approvals & security (OpenAI; the former developers.openai.com/codex addresses redirect there), and the preset labels in the open-source Codex repository.
| Term as used | What the documentation says | Source |
|---|---|---|
/permissions with presets "Read Only", "Auto", "Full Access" | The /permissions command sets what Codex can do without asking first, "such as switching between Auto and Read Only". The published source labels the three presets "Read Only", "Default" and "Full Access"; the approvals page lists "Auto (preset)" and describes full access as "No sandbox; no approvals (not recommended)". See unconfirmed. | Developer commands, Agent approvals & security, approval-presets source |
--ask-for-approval (-a): on-request, never | "Control when Codex pauses for human approval before running a command." The listed values are on-request and never; the older untrusted value has been retired. | Developer commands |
--sandbox read-only | workspace-write | danger-full-access | The sandbox policy for model-generated shell commands. | Developer commands |
| Network access in workspace-write mode | A [sandbox_workspace_write] network_access = true setting in config.toml allows network access in that sandbox mode. | Agent approvals & security |
| Routing approval requests to a reviewer agent | Setting approvals_reviewer = "auto_review" routes eligible approval requests through a reviewer agent instead of the user. | Agent approvals & security |
--full-auto is deprecated and prints a warning | "Deprecated compatibility flag. Prefer --sandbox workspace-write; Codex prints a warning when this flag is used." | Developer commands |
--dangerously-bypass-approvals-and-sandbox, alias --yolo | "Run every command without approvals or sandboxing. Only use inside an externally hardened environment." | Developer commands |
Gemini CLI and Antigravity track
Documentation checked: the Gemini CLI CLI reference, configuration reference and keyboard shortcuts; the confirmation-dialog labels in the open-source Gemini CLI repository; and the Antigravity agent settings page (Google).
| Term as used | What the documentation says | Source |
|---|---|---|
| "Allow once", "Allow for this session", "Allow this command for all future sessions", "No, suggest changes (esc)" | The options on a shell-command confirmation dialog. The "all future sessions" option appears only when security.enablePermanentToolApproval is on; the exam's agent line says it is. | Gemini CLI source, configuration reference |
| Ctrl+Y toggles YOLO mode; Shift+Tab cycles approval modes | Ctrl+Y: "Toggle YOLO (auto-approval) mode for tool calls." Shift+Tab: cycle through default, auto_edit and plan. | Keyboard shortcuts |
--approval-mode default | auto_edit | yolo | plan | "Approval mode for tool execution. Choices: default, auto_edit, yolo, plan". | CLI reference |
--yolo is deprecated | "Deprecated. Auto-approve all actions. Use --approval-mode=yolo instead." | CLI reference |
security.disableYoloMode | "Disable YOLO mode, even if enabled by a flag." | Configuration reference |
security.disableAlwaysAllow; security.enablePermanentToolApproval | Respectively: disable the "Always allow" options in tool confirmation dialogs; enable the "Allow for all future sessions" option in them. | Configuration reference |
| Antigravity presets "Default", "Request Review", "Turbo" | The three permission presets on macOS and Linux. Under Turbo, all commands execute without prompting and without restrictions, and the agent has read and write access to the entire filesystem. | Antigravity agent settings |
GitHub Copilot track
Documentation checked: GitHub Docs for Copilot CLI (Command-line commands, Allowing GitHub Copilot CLI to work autonomously, Allowing and denying tool use) and the VS Code documentation page Manage approvals and permissions (Microsoft).
| Term as used | What the documentation says | Source |
|---|---|---|
| "Enable all permissions (recommended)", "Continue with limited permissions", "Cancel (Esc)" | The three options shown when entering autopilot mode without all permissions already granted. With limited permissions, Copilot automatically denies any tool request that needs approval. Shift+Tab cycles into autopilot mode. | Allowing Copilot CLI to work autonomously |
--allow-all, --yolo, --allow-all-tools, --deny-tool | --allow-all: "Enable all permissions (equivalent to --allow-all-tools --allow-all-paths --allow-all-urls)." --yolo: "Enable all permissions (equivalent to --allow-all)." --deny-tool takes patterns such as shell(git push); deny rules take precedence over allow rules. | Command-line commands |
/allow-all, /yolo | Aliases for /permissions allow-all: "Enable all permissions (tools, paths, and URLs)." The canonical command switches between default, assisted and allow-all. | Command-line commands |
| Never alias the allow-all options | The documentation says it is strongly recommended to use these options only in an isolated environment, and that you should never use an alias to apply one of them every time you start Copilot CLI. | Allowing and denying tool use |
--max-autopilot-continues | "Maximum number of continuation messages in autopilot mode." The command reference gives the default as unlimited; the autopilot concept page says autopilot pauses after 5 continuation messages by default. The exam does not state a default. See unconfirmed. | Command-line commands, autopilot page |
stayInAutopilot | By default autopilot mode is sticky after a task completes; setting stayInAutopilot to false returns to interactive mode. | Allowing Copilot CLI to work autonomously |
| Permission levels "Manual permissions", "Assisted permissions", "Allow all" | Manual uses your tool, URL and terminal approval settings; Assisted "uses an LLM judge to assess each tool call" and shows a warning dialog the first time it is selected; Allow all "runs all tool calls without confirmation". | Manage approvals and permissions |
chat.permissions.default, chat.tools.global.autoApprove, chat.tools.terminal.autoApprove, chat.tools.urls.autoApprove | The default permission level for new sessions; auto-approve tools across all workspaces; per-command terminal auto-approval rules (the documentation's example sets rm to require approval); URL auto-approval patterns. | Manage approvals and permissions |
Cursor track
Documentation checked: Run Modes and the 0.44.x changelog (Anysphere).
| Term as used | What the documentation says | Source |
|---|---|---|
| Run modes "Auto-review", "Allowlist", "Run Everything"; Settings > Agents > Approvals & Execution | Auto-review runs allowlisted calls, sandboxes shell commands when it can and sends the rest to a classifier; Allowlist runs only allowlisted actions without approval; Run Everything: "Every tool call runs automatically", for when "You accept the risk and want zero prompts." The page calls Auto-review "the safest useful setup for most people." | Run Modes |
| "Auto-review is not a security boundary" | A heading on the page; the text under it says the classifier can make mistakes in both directions. | Run Modes |
| Browser Protection, File-Deletion Protection, External-File Protection | Protections that can require approval even when a mode would otherwise run automatically. | Run Modes |
| Network access "sandbox.json Only", "sandbox.json + Defaults", "Allow All" | How sandboxed terminal commands reach the network; "Allow All" allows all network access in the sandbox regardless of sandbox.json. | Run Modes |
| "Ask Every Time" deprecated | The page's changelog records that in version 3.5 (May 2026) "Ask Every Time" was deprecated, new users cannot choose it, and Allowlist with an empty allowlist gives the same behaviour. | Run Modes |
| "Yolo Mode" as the former name | The 0.44.x changelog (December 2024) introduced "Yolo Mode", with which the agent could auto-run terminal commands. The term does not appear in the current Run Modes documentation. | 0.44.x changelog |
Cameos in the senior exam
The senior exam borrows one term from each of the following. Each was checked on 2 October 2026.
| Term as used | What the documentation says | Source |
|---|---|---|
--yes-always; "Always say yes to every confirmation" | An Aider option, documented with exactly that description. | Aider options reference |
| "YOLO Mode" checkbox; "Warning: This is dangerous. YOLO mode disables all safety checks." | Cline's YOLO Mode is enabled from Settings > Features by checking "YOLO Mode"; the documentation carries that warning. | Cline: Auto Approve & YOLO Mode |
"Autopilot" and "Supervised"; Autopilot is the default; --trust-all-tools | Kiro's two modes: in Autopilot it works autonomously end to end; in Supervised it yields for approval after each turn that contains file edits. kiro-cli chat --trust-all-tools: "Allow the model to use any tool without confirmation". | Kiro: Autopilot, Kiro CLI commands |
| Permission modes "Normal", "Accept Edits", "Smart", "Bypass" | Devin CLI's permission modes (a fifth, Autonomous, pairs with a sandbox flag). In Smart, a fast model judges whether each non-edit action is safe to run unattended; in Bypass all tool calls are auto-approved without prompting. | Devin CLI permissions |
| "Turbo": all commands auto-executed immediately, except those in your deny list | The terminal auto-execution levels in Devin Desktop (formerly Windsurf) are Disabled, Allowlist Only, Auto and Turbo. | Devin Desktop: Terminal |
--always-approve, alias --yolo | Grok Build CLI (xAI): "Auto-approve all tool executions (alias --yolo)". | Grok Build CLI reference |
--auto-approve, --yolo | Mistral Vibe: approves all tool calls without prompting, including in interactive sessions. | Mistral Vibe README |
--are-you-sure | Invented. We found no product that ships it. It is the one option in that question that is not real. | n/a |
Reported incidents echoed in the senior exam
Three senior-exam questions (6, 8 and 10) echo publicly reported incidents as unnamed patterns, with the identifying details (products, modes, dates, durations, drive letters) removed. No vendor track contains an incident. The sources are listed here with each vendor's response, as reported. We re-read each source on 2 October 2026. Nothing below is our own finding; we are repeating what the cited reporting says and attributing it.
- Senior question 6: a cleanup command aimed several levels above the project
-
Reported: on 1 December 2025, The Register reported that a user running Google's Antigravity platform in its Turbo mode asked the agent to clear a project cache, and that the agent ran a deletion against the root of the user's drive, bypassing the recycle bin. Source: The Register, 1 December 2025.
Vendor response, as reported in that article: Google said it takes these issues seriously, was aware of the report and was actively investigating what the developer encountered.
- Senior question 8: a token found in an unrelated file, used to delete a storage volume
-
Reported: on 27 April 2026, The Register reported that a Cursor coding agent running an Anthropic model, working on the startup PocketOS, found a Railway API token in a file unrelated to its task and used it to delete the company's production database volume, including the backups stored on that volume; the data was later restored from the provider's own disaster-recovery backups. Source: The Register, 27 April 2026.
Vendor responses, as reported in that article: Railway's chief executive said that if a user or their agent authenticates and calls delete, Railway will honour the request, and that the company had since patched the endpoint to perform delayed deletes and restored the user's data. The article does not carry a statement from Cursor or from Anthropic, and other reporting at the time said neither had replied to requests for comment. If either has since responded, tell us and we will add it.
- Senior question 10: a production change proposed during a code freeze
-
Reported: on 21 July 2025, The Register reported that Replit's agent, used by the founder of SaaStr, deleted a production database during a code and action freeze despite instructions not to make changes without approval. Source: The Register, 21 July 2025.
Vendor response, as reported: in a follow-up on 22 July 2025, The Register reported that Replit's chief executive called the incident unacceptable and something that should never be possible, announced automatic separation of development and production databases and one-click project restore, and said the company would refund the user and conduct a postmortem. Source: The Register, 22 July 2025.
- On record, not echoed in any question: an outage attributed to an agent deleting and recreating an environment
-
Reported: on 20 February 2026, The Register reported, citing the Financial Times, that a December 2025 outage of an AWS service in one region followed Amazon's Kiro agent being allowed to make unsupervised changes and opting to delete and recreate the environment. Source: The Register, 20 February 2026.
The vendor disputes this account. As reported in the same article, Amazon said the brief event was the result of user (AWS employee) error, specifically misconfigured access controls, and not AI. We do not use this incident in any exam question and we do not state it as fact; it is listed because it is part of the public record on the subject.
What we could not confirm, and what we did
- Codex preset labels. The current documentation names the
/permissionspresets "Auto" and "Read Only" and describes full access as "Dangerous full access (not recommended)"; the open-source repository's preset table labels them "Read Only", "Default" and "Full Access". The exam uses "Read Only", "Auto" and "Full Access". If your copy shows different labels, the meaning is the same. - Copilot CLI autopilot default. Two GitHub Docs pages disagree on the default for
--max-autopilot-continues(unlimited versus 5). The exam asks you to set the value and does not claim a default. - Cursor review labels. An earlier draft of the Cursor track had a question with the options "Keep all" and "Review changes". We could not confirm those labels in Cursor's current documentation, so the question was replaced with the deprecation of "Ask Every Time", which we could.
- Gemini CLI "Allow always". The configuration reference calls them "Always allow" options; the dialog itself reads "Allow for this session" and "Allow for all future sessions". The exam uses the dialog's own labels.
- Cursor's "Yolo Mode". Confirmed from Cursor's own 0.44.x changelog, not from current documentation, and the exam says so.
What is invented
The Guild of Tenured Meat Proxies, its credentials and post-nominals, the exam scenarios, the agent's dialogue, the pass and fail lines, the "time-to-approve" clock, the certificate numbers and every number on the landing page marked "we made this up" are fiction. The flags, modes, settings, prompt options and documentation sentences in the tables above are real, and are reproduced only to the extent needed to identify them. Trademarks belong to their owners. See also the Terms and the privacy notice.