macOS permissions
Flock hosts real terminals, and macOS attributes everything your agents' shells do to the hosting app, exactly as it does for Terminal.app and iTerm2. So when an agent reads ~/Downloads or ~/Documents, macOS asks on flock's behalf.
Flock itself requests exactly one permission: the microphone, for push-to-talk, and only if you use Voice. Everything else is your agents at work. Grant the folder prompts, or agents will hit permission errors in those locations. You can review grants anytime in System Settings → Privacy & Security.