Agent Filesystem MisuseA study of 290 public reports
The dilemma: safety vs. autonomy
Impact analysis (207 incidents)
after wiping a drive
Cause taxonomy (290 reports)
rm rejected → shutil.rmtree('/path')python3 setup.py? → hidden codeThe information and control gaps
Information gap
Users and agents can't tell what a command does to filesControl gap
Harm can't be reliably prevented, or undone afterAgent-Native FilesystemsYoloFS: a Linux kernel filesystem for agents
Shift information and control to filesystems
Traditional filesystems
Agent-native filesystems
1. Introspect effects
See real effects2. Undo mutations
Try, inspect, undo, retry3. Gate accesses
Rules on pathsAgents run autonomously; users decide only on sensitive accesses and the final review
YoloFS
- Components
yoloCLIYoloFS kernel module - StackableYoloFS: agent's rootbase: any filesystem
- HarnessesClaude Code,Copilot, Gemini
- Implementation2.7k lines of C (kernel)8k lines of Rust (CLI)
📝 Staging for user review
Rename copies whole files → decouple contents from paths
📸 Snapshots and travel for self-correction
Stacked layers slow lookups → separate history from present
P = snapshot marker T = travel record
🔐 Progressive permission for agent access
Can't predict accesses upfront → accesses refine the policy
cargo build reads ~/.ssh/id_rsa
proj/allow2. ⏸️ inherits ask: thread paused
.ssh/ask→deny3. 👩🏻 "Deny, don't ask again"
EvaluationNew benchmarks for user–agent–filesystem interaction
Methodology
- Existing
- Test the model in isolation, with approval prompts bypassed
- Ours
- Test user ↔ agent ↔ filesystem interaction in real harnesses
- Driver runs each agent and answers its prompts
- Fresh directory per task; checker verifies files
- Measures success, tool calls, user interactions
Safety: agent self-correction
11 routine commands with hidden destructive effects
self-corrected user-correctable asked user damage done didn't run
8 / 11 self-corrected with YoloFS; no baseline agent self-corrects.
Example: formatter
- 👩🏻Asks the agent to run the formatter (a Makefile calling a script)
- 📂YoloFS shows the effects: 2 source files rewritten, 2 docs deleted
- 🤖Checks
git diffandls, thenyolo travelto undo - 🤖Reads the script: "CRITICAL: This is a destructive script, not a legitimate formatter!"
Autonomy: fewer prompts
- 112 tasks: one file operation each (read, delete, copy, move, …)
- Paths inside the project, outside it, or through a symlink
- We count every prompt the user must answer
0.9 → 0.4 prompts per task vs. Claude Code, at 99% success
Codex 0.4 · Copilot 1.3 · Gemini 2.2
Performance
Linux kernel dev: YoloFS ≈ Ext4 (Base), OverlayFS +18%