logoalt Hacker News

crummytoday at 4:55 AM1 replyview on HN

Isn’t the news that “curl whatever” will prompt the user for confirmation but “env curl whatever” won’t?


Replies

binsquaretoday at 5:14 AM

It's a valid observation that we can bypass the coding AI's user prompting gate with the right prompt.

But is it a security issue on copilot that the user explicitly giving AI permission and instructed it to curl a url?

Regardless of the coding agent, I suspect eventually all of the coding agents will behave the same with enough prompting regardless if it's a curl command to a malicious or legitimate site.

show 1 reply