‹ BackHN Continuity

Thread

Humans missed 1 in 3 threats approving AI agent commands across 40k game runs

233 points · 182 comments · Wirbelwind

  1. sigseg1v · · focus · HN ↗
    If there is an objectively correct right or wrong answer for a given command, why even ask? In that case there should be a configuration page where the user sets up if they want commonly used credentials to be accessible or not, and then there's no prompts.
    1. dgunay · · focus · HN ↗
      In a lot of cases there is, but you have to be aggressive about allowlisting commands.

      Also the permissioning system for Codex and Claude Code, while not useless, is insufficiently expressive for a lot of tools which are safe if used a certain way, but unsafe otherwise. For example, the 99% use case of ripgrep (searching for text) is safe, but using the --pre flag makes it able to run arbitrary code. Both of their permissioning systems cannot block flags at arbitrary positions though, so you have to resort to either hooks or aliasing if you want to do this.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.