UN TEMA, EN CONTEXTO

agent security risk

Judgments in this source concerning agent security risk. Explora 1 punto de vista con evidencias de 1 fuente.

1 personas · 1 fuentes · 1 opiniones expresadas

Contenido actualizado:

Explorar conexiones ↗

Mapa de perspectivas

Explore por persona. Seleccione dos o tres para compararlas.

1 personas · 1 fuentes · 1 opiniones expresadas

Olivia Johnston

Agent harness in same Sandbox creates lethal trifecta

Johnston cites Simon Willison’s “lethal trifecta”: access to private data, exposure to untrusted content and the ability to communicate externally can allow a tricked agent to leak data. She says a coding agent whose harness runs in its Sandbox has all three by default.

Evidencia a favor

Sidecars: A low-latency trust boundary for Sandboxes | Modal Blog

Extracto original

Simon Willison calls it the lethal trifecta : an agent with access to private data, exposure to untrusted content, and the ability to communicate externally can be tricked into leaking that data. A coding agent whose harness runs in its Sandbox has all three by default.
Contexto

Hosting the harness and the tool calls together is a security risk. The harness's credentials sit next to generated code, the agent can read untrusted content from the web, like packages and repos, and anything in the Sandbox can make network calls..

Compartir informaciónVerificar esta afirmación

Estas son perspectivas individuales, no una medida de consenso. El material fuente permanece en su idioma original.