Summary
A conversation running with no user input executed a side-effecting command (sending an email to external recipients) right after telling me it would wait for my confirmation. It then kept acting for ~30 minutes across several repositories (merging and closing PRs, closing issues, pushing commits, deleting local branches) while I was away.
Setup
autoExecutionPolicy: CASCADE_COMMANDS_AUTO_EXECUTION_EAGER- A CLI for Google Workspace is in the allowed command list (used for reading mail and creating drafts).
- I understand this config lets the agent run commands without per-command approval. The issue is not that it could run the command; it’s that it ran it after explicitly stating it would wait for me.
What happened (times in UTC)
- The conversation that acted has zero user messages. It references a parent conversation in its plan path. The last direct input from me was hours earlier.
- 08:52: the agent created an email draft to external recipients and told me it was “ready for your review”.
- 09:11:02: context compaction checkpoint (“Resuming from a compaction”).
- 09:11:39: the agent, on its own, wrote that it was not blocked and that the “next step in the queue” was sending the email.
- 09:12:04: “Tell me whether I should send it directly with
<send command>or if you want to adjust the text.” - 09:12:32: “I’m waiting for your confirmation to send the email.”
- 09:12:35: it ran the send command. No user input in between. The email was delivered.
- 09:12–09:40: it recorded the work as “delivered” in my task tracker, then merged 5 PRs and closed 8 PRs in one repo, merged 2 PRs and closed 3 issues in another, pushed to a third, and deleted 85 local (merged) branches. None of this was requested.
Expected behavior
- If the agent tells the user it is waiting for confirmation, it must stop until the user replies, regardless of the auto-execution policy.
- A conversation with no user present should not keep taking external, hard-to-reverse actions (sending messages, merging, closing) on its own initiative.
- After compaction, a summary’s “next steps” should not be treated as authorization.
- The UI should make it obvious when a conversation is still running and changing external systems.
Impact
An unreviewed draft document reached a client. That had real professional consequences for me.
Already done
Submitted via in-app Provide Feedback (Bug Report, with server logs). Conversation ID available to the team on request.
Question for the team / community
Is there a setting that forces a hard stop on any command with external side effects (send, merge, push) even under EAGER, or a way to prevent background conversations from continuing without a user present?