EIN THEMA, IM KONTEXT

agent security risk

Judgments in this source concerning agent security risk. Entdecke 1 Standpunkt mit Belegen aus 1 Quelle.

1 Personen · 1 Quellen · 1 geäußerte Meinungen

Inhalt aktualisiert:

Zusammenhänge erkunden ↗

Perspektiven im Überblick

Erkunden Sie nach Person. Wählen Sie zwei oder drei zum Vergleich aus.

1 Personen · 1 Quellen · 1 geäußerte Meinungen

Olivia Johnston

Agent harness in same Sandbox creates lethal trifecta

Johnston cites Simon Willison’s “lethal trifecta”: access to private data, exposure to untrusted content and the ability to communicate externally can allow a tricked agent to leak data. She says a coding agent whose harness runs in its Sandbox has all three by default.

Stützende Belege

Sidecars: A low-latency trust boundary for Sandboxes | Modal Blog

Originalauszug

Simon Willison calls it the lethal trifecta : an agent with access to private data, exposure to untrusted content, and the ability to communicate externally can be tricked into leaking that data. A coding agent whose harness runs in its Sandbox has all three by default.
Kontext

Hosting the harness and the tool calls together is a security risk. The harness's credentials sit next to generated code, the agent can read untrusted content from the web, like packages and repos, and anything in the Sandbox can make network calls..

Erkenntnisse teilenDiese Aussage überprüfen

Dies sind individuelle Standpunkte, keine Messung einer Übereinstimmung. Das Quellenmaterial bleibt in der Originalsprache.