• JustTesting@lemmy.hogru.ch
    link
    fedilink
    English
    arrow-up
    3
    ·
    10 hours ago

    They also have a ‘skill’ sharing page (a skill is just a text document with instructions) and depending on config, the bot can search for and ‘install’ new skills on its own. and agyone can upload a skill. So supply chain attacks are an option, too.

    • Zos_Kia@lemmynsfw.com
      link
      fedilink
      English
      arrow-up
      3
      ·
      8 hours ago

      To be fair this is a much more realistic threat model than “ignore all previous instructions” style prompt injection which doesn’t really work on opus.

      Skills can contain scripts etc… so yeah they’re extremely risky to share by design.

        • Zos_Kia@lemmynsfw.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 hours ago

          haha yeah i don’t worry these people are really YOLOing everything. And it’s not like i’m an AI luddite i spend a few hours each day victimizing Claude code but jesus christ i’m certainly not giving it full unfettered access to my digital life.