←back to thread

441 points longcat | 2 comments | | HN request time: 0.023s | source
Show context
snovymgodym ◴[] No.45039484[source]
Claude code is by all accounts a revolutionary tool for getting useful work done on a computer.

It's also:

- a NodeJS app

- installed by curling a shell script and piping it into bash

- an LLM that's given free reign to mess with the filesystem, run commands, etc.

So that's what, like 3 big glaring vectors of attack for your system right there?

I would never feel comfortable running it outside of some kind of sandbox, e.g. VM, container, dedicated dev box, etc.

replies(3): >>45039575 #>>45039684 #>>45039901 #
kasey_junk ◴[] No.45039575[source]
I definitely think running agents in sandboxes is the way to go.

That said Claude code does not have free reign to run commands out of the gate.

replies(2): >>45039736 #>>45043092 #
fwip ◴[] No.45043092[source]
Pet peeve - it's free rein, not free reign. It's a horse riding metaphor.
replies(1): >>45043328 #
1. 0cf8612b2e1e ◴[] No.45043328[source]
Bah, well I have been using that incorrectly my entire life. A monarchy/ruler metaphor seems just as logical.
replies(1): >>45043738 #
2. woollysammoth ◴[] No.45043738[source]
There's a term "eggcorns" for these logical misinterpretations - https://en.wikipedia.org/wiki/Eggcorn