logoalt Hacker News

falloutxlast Friday at 8:47 PM1 replyview on HN

Still leaves you open for data exfil. Your AI goes to a site to check documentation, but oh no that site wants it to make an API call with a very specific token.


Replies

9devlast Friday at 8:55 PM

Claude will only ever ask if it is allowed to connect to the domain name, so if it got a malicious link from a web search, you’re SOL anyway.

show 1 reply