logoalt Hacker News

comboytoday at 10:31 AM2 repliesview on HN

Interesting attack, very nicely designed. Not sure if it's much related to the auto mode itself though.


Replies

kevsimtoday at 10:33 AM

The point is that auto mode gives people a false sense of security that leads them to believe they don't need to run Claude in a proper sandbox. This same attack running in a sandbox (even in YOLO mode) would be comparatively harmless.

show 3 replies
yeputonstoday at 11:00 AM

I don’t think it’s related to the auto mode at all. It would work perfectly in the manual mode. It does not even need Claude: just give a human a similar archive and hope they run some simple Python from the directory at least once. And make sure there are lots of files do they don’t notice a weird .py around

show 1 reply