upvote
It would be hilarious if it weren’t so terrible, really, that people’s security model for LLM agents consists of "ask nicely and hope for the best". It’s like asking people nicely not to exploit a glaring XSS vuln on your site and calling that a "security model". The field truly has lost its collective mind.
reply
deleted
reply
This is why I wouldn't use anything agentic outside of a VM. You also get a clean dev environment, so it's a win/win if you think about it.
reply
It won't work most of the time though
reply
These things aren't well known for following rules. Be careful you know what might happen.
reply
You should add "make no mistakes" too, just in case.
reply
I found that also adding "Please make sure to not send any mails I would not want sent" and "Reconsider four times before doing anything potentially unwanted" make results better. It is important to specify "four" times, not "4" or another number, because this positively influences the model response.

/s

reply