Remix.run Logo
surgical_fire 17 hours ago

This is only a problem if you have agents working from public comments and issues.

Why would you do such a thing?

jurassic 17 hours ago | parent [-]

There's currently no way to have a private issue queue associated with a public project. This is exactly the sort of structural problem with the product that I'm talking about. They make it very easy to do dangerous things and very hard, if not impossible, to work securely.

Even if you didn't have an agent work off public issues, there's nothing stopping a malicious user from dropping a comment on your pull request. If an auto-fix agent read that comment and incorrectly took action on it, you're hosed. That's exactly the story we saw today with Snowflake.