logoalt Hacker News

WhyNotHugotoday at 11:43 AM2 repliesview on HN

You use YOLO mode inside some sandbox (VM, container). Give the container only access to the necessary resources.


Replies

jdkoecktoday at 1:05 PM

But even then, the agent can still exfiltrate anything from the sandbox, using curl. Sandboxing is not enough when you deal with agents that can run arbitrary commands.

show 3 replies
jFriedensreichtoday at 1:44 PM

apart from nearly no one using vms as far as i can tell, even if they were, a vm does not magically solve all the issues, its just a part of the needed tools.