智能体 harness 位于同一 Sandbox 中构成致命三角
Johnston 引用了 Simon Willison 的“致命三角”:访问私有数据、暴露于不受信任的内容以及对外通信的能力,这三者可能让被欺骗的智能体泄露数据。她表示,一个其 harness 在自身 Sandbox 中运行的编码智能体默认就同时具备这三项条件。
支持这项说法
西蒙·威利森(Simon Willison)将其称为“致命三重组合”:一个能够访问私有数据、接触不可信内容,并具备对外通信能力的智能体,可能被诱骗而泄露该数据。一个运行于沙箱(Sandbox)中的编码智能体,其执行环境(harness)默认即同时具备这三种特性。
原始摘录
Simon Willison calls it the lethal trifecta : an agent with access to private data, exposure to untrusted content, and the ability to communicate externally can be tricked into leaking that data. A coding agent whose harness runs in its Sandbox has all three by default.
上下文
将执行环境(harness)与工具调用(tool calls)共同托管存在安全风险:执行环境的凭据与生成的代码并置;智能体可从网络(例如软件包和代码仓库)读取不可信内容;且沙箱内任何内容均可发起网络请求。
原始上下文
Hosting the harness and the tool calls together is a security risk. The harness's credentials sit next to generated code, the agent can read untrusted content from the web, like packages and repos, and anything in the Sandbox can make network calls..