upvote
> I many scenarios, e.g. running the harness server-side, as is the case for chat interfaces, you don't really want to expose OS shell access as that opens up a huge security attack surface.

It does, but a restricted user account mitigates the large majority of those issues. A sandbox mitigates even more.

The number of remaining exploits left is probably going to be the same as the number in the harness. More, in fact, as many of them have no human review anyway.

reply
You can give the LLM a bash without giving it the full /usr/bin.

That's been a trivially solved problem for decades.

reply
That has been one of the most common exploits for decades.
reply
And as a result it is the most hardened.
reply
Yes, and also MCP does literally nothing to prevent these sorts of exploits.

Like I said, AI bros vibecoding slop because they literally have no clue what they're doing.

reply