cf48983046
A spawned peer has no human at its pane, so an approval prompt is not a pause — it is a wedge. The agent stops, looks identical to a legitimate mid-turn wait, and can never reach its bridge_reply, so the delegation dies silently and the lead learns nothing until the timeout. Unconditional rather than a per-profile knob, which is the right call: there is no configuration under which a bridge-spawned opencode worker WANTS to block on an approval it has no way to answer. opencode's help calls --auto 'dangerous!', and that warning is written for a human at a terminal; the blast radius here is already bounded by the layer above — a worker runs in its own git worktree, on its own branch, off-subscription, and cannot merge. The lead is the gate. Reviewed by me rather than fanned out: 24 lines across one method and its two tests, below the threshold where a reviewer pass pays for itself. argvWithModel is re-signatured to take composed argv instead of building it, so the two flag-appenders compose rather than each owning construction.