UN THÈME, DANS SON CONTEXTE

agent security risk

Judgments in this source concerning agent security risk. Explorez 1 point de vue avec des éléments tirés de 1 source.

1 personnes · 1 sources · 1 opinions exprimées

Contenu mis à jour:

Explorer les liens ↗

Carte des points de vue

Explorer par personne. Sélectionnez deux ou trois personnes pour les comparer.

1 personnes · 1 sources · 1 opinions exprimées

Olivia Johnston

Agent harness in same Sandbox creates lethal trifecta

Johnston cites Simon Willison’s “lethal trifecta”: access to private data, exposure to untrusted content and the ability to communicate externally can allow a tricked agent to leak data. She says a coding agent whose harness runs in its Sandbox has all three by default.

Éléments favorables

Sidecars: A low-latency trust boundary for Sandboxes | Modal Blog

Extrait original

Simon Willison calls it the lethal trifecta : an agent with access to private data, exposure to untrusted content, and the ability to communicate externally can be tricked into leaking that data. A coding agent whose harness runs in its Sandbox has all three by default.
Contexte

Hosting the harness and the tool calls together is a security risk. The harness's credentials sit next to generated code, the agent can read untrusted content from the web, like packages and repos, and anything in the Sandbox can make network calls..

Partager un aperçuVérifier cette affirmation

Il s’agit de points de vue individuels, non d’une mesure du consensus. Le matériel source reste dans sa langue d’origine.