←back to thread

Living Dangerously with Claude

(simonwillison.net)
134 points FromTheArchives | 1 comments | | HN request time: 0.224s | source
Show context
matthewdgreen ◴[] No.45677089[source]
So let me get this straight. You’re writing tens of thousands of lines of code that will presumably go into a public GitHub repository and/or be served from some location. Even if it only runs locally on your own machine, at some point you’ll presumably give that code network access. And that code is being developed (without much review) by an agent that, in our threat model, has been fully subverted by prompt injection?

Sandboxing the agent hardly seems like a sufficient defense here.

replies(3): >>45677537 #>>45684527 #>>45686450 #
simonw ◴[] No.45677537[source]
What is your worst case scenario from this?
replies(3): >>45682120 #>>45684850 #>>45686312 #
1. noitpmeder ◴[] No.45682120[source]
Bank accounts drained, ransomware installed, ...