top | item 45669850

(no title)

codebastard | 4 months ago

The security paradox of executing unverified code.

If you are executing local malicious/unknown code for reasons you need to read this...

discuss

order

wmf|4 months ago

This vulnerability comes from allowing the AI to read untrusted data (usually documentation) from the Internet. For LLMs the boundary between "code" and "data" isn't as clear as it used to be since they will follow instructions written in human language.