YOLO modes are useful, and a lot more productive than trying to do one-by-one approvals. But you just need to devise a policy about what your blast radius is (what are you willing to lose, and what kind of recovery cost are you willing to play?) ahead of time and use some external boundary (OS sandbox, container, VM) to enforce it.
You should think of these as "I, the developer, am handling containment myself" modes, not "there is no containment" modes.