The OpenAI talk at DefCon shows what can happen when you let these things run without any human intervention.
The solution is, obviously, even less human intervention. 🤦🏻♂️
The OpenAI talk at DefCon shows what can happen when you let these things run without any human intervention.
The solution is, obviously, even less human intervention. 🤦🏻♂️
The issue is the whole UX behind it. I have yet to see someone review the 30th prompt of "grep" - there is no same default or middle ground.
For example whitelist read actions or harness side limitations to the project folder.
This is just lazy - again. "Users don't use or very bad security feature so they just want us to disable it".
Auto mode sounds less like security and more like outsourcing judgment to the same AI you’re supposedly trying to constrain. If users are bad at spotting malicious prompts, the answer shouldn’t be: great, let’s remove them from the loop entirely. That’s not safety. That’s automated permission laundering.
So if I remember correctly, what happens with auto mode is they run a second smaller LLM called the "classifier" to evaluate the tool uses of the main one.
I've used auto mode at work now for many months, and it approves most things because most things Claude does are reasonable.
Once or twice I have seen it reject Claude. I can't remember the exact scenario, but I had asked Claude to diagnose an issue but not fix it yet, and when later on it tried to make the change the classifier rejected it, giving the reason that what it was trying to do did not match my request.
In my opinion, the trick to using auto mode safely here is to:
That’s not safety. That’s automated permission laundering.
*Twitches*
Hooray, uncontrolled and unregulated consumption of tokens. What could go wrong? /s
This is a most excellent place for technology news and articles.