(no title)
LudwigNagasena | 1 month ago
And it is simply easier to whitelist directories than individual commands. Unix utilities weren't created with fine-grained capabilities and permissions in mind. Wherever you add a new script or utility to a whitelist, you have to actively think whether any new combination may lead to privileges escalation or unintended effects.
zahlman|1 month ago
No, you don't. You have a command generated by auditable, conventional code (in the agent wrapper) rather than by a neural network.
VTimofeenko|1 month ago