AI Permission Review: who answers when your agent asks
Halfway through a task, the agent stops to ask "Run this command?" — and you happen to be away from the screen. The whole job sits there waiting for you. AI Permission Review reads these permission prompts for you: dangerous ones are held for you, safe ones get a suggestion or a key press on your behalf.
It does exactly one thing: answer the agent's permission prompts, one key at a time. It never types commands for you and never touches anything beyond what's on screen.
- The agent stops and waitsAgentmux detects a permission prompt
- Read the screenFind the current prompt and redact sensitive text
- BlacklistA dangerous command matchedHanded to you
- AllowlistA command you trust matched; pick the key locally
- AI judgmentAllow, deny, or unsureDeny or unsure: handed to you
- Re-check before sendingIf the screen changed, nothing is sentHanded to you
- Suggest, or press for youDepends on the mode you picked
When it starts
It only starts when an agent stops and waits for you. Agentmux already tracks the state of agents like Claude Code and Codex. When a prompt such as "Allow this?" or "Pick 1 or 2" appears, the session is marked as waiting, and the review begins at that moment.
These also need to be true:
- The AI Permission Review switch in Settings is on.
- The session's mode is Advisor or Auto Reply, not Off.
- You have Pro, or you're still in the free trial.
Each prompt is judged once; it doesn't re-ask every few seconds. As soon as you press a key or type in the terminal yourself, any judgment in progress is cancelled and your input wins.
Sessions that aren't on screen are reviewed too. When you switch to another tab, it keeps watching in the background.
Step one: read the screen
It first picks out the current prompt on screen: the command to run, the question itself, and the choices you can pick. Older content that has scrolled up doesn't count.
Before anything goes to the AI, text that looks like a password, API key, or token is redacted. If redaction fails, the original text is not sent, and no key is pressed this time.
First check: the blacklist
The blacklist is matched right on your phone and always runs first. A match is never sent to the AI; it's handed straight to you. The built-in rules cover the most dangerous kinds of operations:
rm -rfon/,~, or your home directorysudogit push --force(--force-with-leasedoesn't count)DROP TABLE,DROP DATABASE,TRUNCATE TABLE- Piping something downloaded straight into a shell, like
curl … | sh - Commands that write directly to a disk, like
mkfsanddd if=
You can edit or remove these built-in rules, and add your own.
Second check: the allowlist
Some commands you approve every day, like running tests or a build. Add them to the allowlist, and the next match is decided right on your phone — which key to press, with no wait for the AI and no API usage.
In Auto Reply mode, you can also turn on "Allow all commands in this session" for a single session. It skips AI judgment, but the blacklist still applies, and it turns off when the session ends.
If the allowlist matches but there's no clear, safe key to press on screen, the prompt is handed to you.
Third check: AI judgment
Only prompts that match neither list go to the AI. It sees the redacted screen and your Main Intent — what you want the agent to do this time, such as "fix the login page tests".
You can choose between two engines:
- JEV decision engine (through OpenRouter or TypeSafe): built for terminal prompts, and fast. It judges in three levels: read-only, safe operations are allowed; commands that match your Main Intent are allowed; everything else — unrelated, unclear, or high-risk — is handed to you. Anything that looks suspicious or like a malicious injection is denied outright.
- An OpenAI-compatible LLM: OpenAI, OpenRouter, or a model you run on your own machine.
The AI reaches one of three conclusions: allow, deny, or unsure. Only "allow" goes further, and the AI has to name exactly which option on screen to pick. It never picks a permanent choice such as "Always allow" or "Don't ask again".
Finally: suggest, or press for you
Each session has its own mode:
- Advisor (default): suggestions only. A notice at the top of the screen tells you what it recommends, with an Accept button next to it. Nothing is sent until you tap it.
- Auto Reply: when the verdict is allow, it presses the key for you and shows a notice saying what it pressed.
Either way, it looks at the screen again right before sending a key. If the prompt changed, the options moved, or the cursor isn't on the target, nothing is sent. This keeps a change in the few seconds of judgment from turning into the wrong choice.
After Auto Reply sends a key, it waits 3 seconds before it can send another in the same session.
When it always hands the prompt to you
- A blacklist rule matched.
- The AI said deny, or wasn't sure.
- It can't tell which key the prompt wants.
- The choice is a permanent grant like "Always allow".
- The screen changed before the key was sent.
- Redacting sensitive text failed.
When that happens, Agentmux alerts you the usual way, exactly as it would with the review turned off.
Getting started
Before you start, have one of these ready:
- An API key for the JEV engine, from OpenRouter or TypeSafe.
- Your own OpenAI-compatible LLM endpoint, such as the OpenAI API or a model running on your own computer.
- Open Settings → AI Permission Review and turn on the switch. The first time, you'll see an explanation of what data is shared. Tap to agree, and you're taken straight to Advanced Settings.
- In Advanced Settings, choose an engine, enter your API key, and tap "Test AI Endpoint Connection" to make sure it works.
- Back in Settings, write down your Main Intent. Each session can have its own, too.
- Connect to a server, start an agent, tap the Permission Review button in the terminal toolbar, and choose Advisor or Auto Reply.
AI Permission Review is currently available on iOS only.
Try Advisor for a few days first to see whether its suggestions match how you work, before turning on Auto Reply for specific sessions.
Where your data goes
Only redacted screen excerpts and your Main Intent are sent, to the AI service you set up, using your own API key. Agentmux doesn't provide or relay any AI service. A record of each decision stays on your device only; you can review or clear it in the audit log. Model reasoning is never stored.