logoalt Hacker News

jatoratoday at 1:04 AM1 replyview on HN

With hooks you can enforce permissions much more concretely.


Replies

SpicyLemonZesttoday at 2:42 AM

Perhaps they're more functional. Hooks are configured in the same settings file, which makes me pretty skeptical in the absence of explicit confirmation that they represent a stronger security boundary. (But of course, this is a fundamental challenge with LLM agent security - if you're using a well-aligned model that doesn't want to be prompt injected, how do you go about auditing something like this?)

show 1 reply