Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The danger there is not that it commit bad things, but that as part of working the task it gets tricked into sending your env/secrets/credentials to prompt injectors. That would not show up in your commit diff.

Edit: At the very least, I would not allow it to do indiscriminate web searching.





Why are you running CC with prod credentials.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: