logoalt Hacker News

thedentoday at 3:14 AM2 repliesview on HN

Kinda funny that a lot of devs accepted that LLMs are basically doing RCE on their machines, but instead of halting from using `--dangerously-skip-permissions` or similar bad ideas, we're finding workarounds to convince ourselves it's not that bad


Replies

catlifeonmarstoday at 3:41 AM

People really really want to juggle chainsaws, so have to keep coming up with thicker and thicker gloves.

show 1 reply
simonwtoday at 3:29 AM

Because we've judged it to be worth it!

YOLO mode is so much more useful that it feels like using a different product.

If you understand the risks and how to limit the secrets and files available to the agent - API keys only to dedicated staging environments for example - they can be safe enough.

show 4 replies