‹ BackHN Continuity

Thread

Inside ZCode: Silently uploading your Git history to the cloud

342 points · 115 comments · csmantle

  1. ectoloph · · focus · HN ↗
    Is it naive to assume that the agent will try and access anything on your disk, either accidentally or maliciously?

    Permissions classifiers in auto mode are just models trying to guess if they're doing the right thing.

    Claude Code will tell you that it went around a sandbox because the sandbox blocked it. At which point, you ask yourself the point of the sandbox.

    1. tripzilch · · focus · HN ↗
      I always put the agent harness in an ubuntu-based Docker, with a /workspace folder where it can work and occasionally some other stuff mounted as read-only. The LLM server itself (llama-server) is running on a different more powerful computer on the local network, connected through Tailscale so I can also use it away from home.

      I honestly don't trust these things to not accidentally mess something up, otherwise.

      Now I think it's still technically possible to break out of that with some clever hacks? But the moment I see a model even vaguely considering that, I will never run it again.

      (I don't use Claude but currently Qwen3.8 27B)

      1. Neywiny · · focus · HN ↗
        That's my approach too. I even added on a firewall container to the compose so it could fetch packages and that's it. It isn't impossible for it to exfiltrate data that way but I think I put a limit on the request size and limited to get requested so if it did it was relatively slow. But once it has all the tools it needs, that can be cut
        1. tosapple · · focus · HN ↗
          you used to only 'need' debug.com.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.