logoalt Hacker News

veganmosfettoday at 4:22 PM3 repliesview on HN

The reseller could use an intermediate proxy and modify the traffic like in [1], to get control of the client machine - depending on the harness permissions.

TLS terminates at the proxy (say, https://reselltokens.ai), end to end integrity is not enforced. LLM traffic contains tool calls like "bash ...", which are executed on the client machine, they can be manipulated. Secret exfil is also possible.

[1] https://arxiv.org/html/2604.08407v1


Replies

rdbelltoday at 4:56 PM

You can place your own CLIProxyAPI instance in front of the reseller proxy and block prompts/responses that look harmful.

There are community plugins like this: https://github.com/rheodev/cpa-plugin-privacyfilter

I haven't tried the plugin system myself yet.

show 1 reply
andaitoday at 6:26 PM

Nice, he can help fix my Linux Bluetooth audio issues.

MerriBantoday at 4:53 PM

[flagged]