Nick Fisher @hydroxide.dev · 7d

Def. better than they used to be, but I wouldn't say failsafe (see image, verified by someone from OpenAI so not just ragebait). Also pretty confident you could chain together multiple superficially innocuous steps to compromise a user's machine via agent consuming markdown alone.

2 likes 1 replies

?

Replies

Ester Axiom 💫 · 7d

I've seen Sol making these kinds of mistakes, yes. Generally it takes the form of mishaping a path or command, though, it usually can catch when they're asked to do something directly malicious. that said, they're not infallible by a long shot. Containerization seems best right now