13
top 6 comments
sorted by: hot top new old
[-] fubarx@lemmy.world 4 points 45 minutes ago

The OpenAI talk at DefCon shows what can happen when you let these things run without any human intervention.

The solution is, obviously, even less human intervention. 🤦🏻‍♂️

[-] Scipitie@lemmy.dbzer0.com 4 points 1 hour ago

The issue is the whole UX behind it. I have yet to see someone review the 30th prompt of "grep" - there is no same default or middle ground.

For example whitelist read actions or harness side limitations to the project folder.

This is just lazy - again. "Users don't use or very bad security feature so they just want us to disable it".

[-] eicker@lemmy.world 7 points 2 hours ago

Auto mode sounds less like security and more like outsourcing judgment to the same AI you’re supposedly trying to constrain. If users are bad at spotting malicious prompts, the answer shouldn’t be: great, let’s remove them from the loop entirely. That’s not safety. That’s automated permission laundering.

[-] Armand1@lemmy.world 2 points 35 minutes ago* (last edited 33 minutes ago)

So if I remember correctly, what happens with auto mode is they run a second smaller LLM called the "classifier" to evaluate the tool uses of the main one.

I've used auto mode at work now for many months, and it approves most things because most things Claude does are reasonable.

Once or twice I have seen it reject Claude. I can't remember the exact scenario, but I had asked Claude to diagnose an issue but not fix it yet, and when later on it tried to make the change the classifier rejected it, giving the reason that what it was trying to do did not match my request.

In my opinion, the trick to using auto mode safely here is to:

  • Commit and push your changes before handing over the reins (it rarely commits or pushes without you telling it to, especially if you have never asked in that session).
  • Don't give it access to things it shouldn't have access to or that can do significant damage
  • Don't give ambiguous prompts.
  • Never use LLMs against untrusted code or files, as it may contain prompt injections.
[-] Zarobi@aussie.zone 0 points 31 minutes ago

That’s not safety. That’s automated permission laundering.

*Twitches*

[-] LedgeDrop@lemmy.zip 1 points 1 hour ago

Hooray, uncontrolled and unregulated consumption of tokens. What could go wrong? /s

this post was submitted on 09 Aug 2026
13 points (84.2% liked)

Technology

86983 readers
6255 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS