upvote
> When I use LLMs I leave things as open as possible. I just give them the information they need and my ask.

How do you handle security?

Both “internally” against e.g. data loss, I’m assuming via limiting the harness, and “externally”, i.e. stuff like prompt injection risks?

reply
Sandboxing and reviewing the output. I don't have any incredible insight to add here- that's the same process I think most of us are doing.
reply
This vibe people sentiment is not wrong per se.

If you want outlier performance from these models it is best to just ask in the most high level prompt of the most minimal harness and let them loose.

Any extra information reduces their performance.

However, as often as these models output masterpieces, they also produce utter garbage so our current choice is for them to have a process to follow that can be reviewed by humans and LLMs.

reply
That works for well trod paths, e.g “fix ci” works exceedingly well. “why app slow” obviously doesn’t work because the task is underspecified. But in order to properly specify you either need an experienced engineer who knows how to narrow the problem domain, or you have to provide some template instructions/output formats (e.g, skills) which will invariably never fit the problem perfectly
reply
> . “why app slow” obviously doesn’t work because the task is underspecified.

Not always. In my case LLM goes to grafana mcp, pulls metrics/traces/cpu profiles. Figures out what is slow and proposes a solution.

reply
I wouldn't agree. Sota models can do self-directed sampling, profiling, benchmarking, read call trees, etc. to give you a report of the app's bottlenecks and then recommend solutions that can be vetted.

I do this constantly.

As the upstream comment points you, you don't need to specify. Sota models are that good. And by being overprescriptive you can accidentally shut off branches that they would've taken, downgrading the quality of their work.

reply
In my experience if you’re at the point where you have something to sample then the hard part is already done.

In a perfect world everything is covered by distributed tracing and the problems are only in your application code and the agent just needs to find the data

In reality the data is often missing or misleading. “Your observability sucks”? Yeah, but that’s life

reply
> “Your observability sucks”? Yeah, but that’s life

You could start by asking your AI "help me add better observability to our stack"

reply
I use skills. The skills are not typically "how to perform a task in detail" they are more about what relevant tools and knowledge are required to work in a domain. That is I give the LLM the information it needs about the system but not a sequence of how to accomplish a task. I treat it more like a human and less like a computer.
reply
It really doesn’t need to be that much more specified, give it context to the tools and level of analysis you expect then “why app slow” is a reasonable prompt
reply