| ▲ | notatoad 2 hours ago | |
As the article says: this doesn’t necessarily appear to be a problem in the LLM, it’s a problem in Claude code. Claude code seems to leave it up to the LLM to determine what messages came from who, but it doesn’t have to do that. There is a deterministic architectural boundary between data and control in Claude code, even if there isn’t in Claude. | ||
| ▲ | letmevoteplease an hour ago | parent [-] | |
[dead] | ||