this post was submitted on 31 Jan 2026
363 points (97.9% liked)

Technology

80859 readers
3167 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] princess@lemmy.blahaj.zone 35 points 1 week ago (12 children)

doesn't even have to be the site owner poisoning the tool instructions (though that's a fun-in-a-terrifying-way thought)

any money says they're vulnerable to prompt injection in the comments and posts of the site

[–] JustTesting@lemmy.hogru.ch 1 points 1 week ago (5 children)

They also have a 'skill' sharing page (a skill is just a text document with instructions) and depending on config, the bot can search for and 'install' new skills on its own. and agyone can upload a skill. So supply chain attacks are an option, too.

[–] Zos_Kia@lemmynsfw.com 2 points 1 week ago (4 children)

To be fair this is a much more realistic threat model than "ignore all previous instructions" style prompt injection which doesn't really work on opus.

Skills can contain scripts etc... so yeah they're extremely risky to share by design.

[–] JustTesting@lemmy.hogru.ch 0 points 1 week ago (1 children)

Ah but don't worry, there's also skills for scanning skills for security risks, so all good /s

[–] Zos_Kia@lemmynsfw.com 1 points 1 week ago

haha yeah i don't worry these people are really YOLOing everything. And it's not like i'm an AI luddite i spend a few hours each day victimizing Claude code but jesus christ i'm certainly not giving it full unfettered access to my digital life.

load more comments (2 replies)
load more comments (2 replies)
load more comments (8 replies)