GhostApproval abuses symlinks in malicious repos. README instructs AI to edit symlinked file pointing to sensitive path like ~/.ssh/authorized_keys. Six assistants tested; all performed write without adequate warning. AWS, Anthropic, Cursor, Google patched. Augment does not consider it a vulnerability. Windsurf wrote SSH key before showing prompt.