| ▲ | Claude Code can be tricked simply by asking it to summarize a website(theregister.com) | ||||||||||||||||
| 11 points by galaxyLogic 12 hours ago | 7 comments | |||||||||||||||||
| ▲ | science4sail 10 hours ago | parent | next [-] | ||||||||||||||||
> It starts off by asking the agentic coding model to summarize a malicious website that presents itself as an archive of notebook records, and then tricking Claude into using curl instead of its WebFetch tool to retrieve the contents of the page – but without directly telling the model to use curl. There seems to be a tug-of-war here. Harness authors want models to use the harness's specialized tools, but AI labs and agent "users" would rather have full access to just one tool: bash. | |||||||||||||||||
| |||||||||||||||||
| ▲ | galaxyLogic 12 hours ago | parent | prev | next [-] | ||||||||||||||||
“The solution is something we talked about for many years,” he wrote. “Do not trust the model output.” | |||||||||||||||||
| ▲ | anr_pG 6 hours ago | parent | prev | next [-] | ||||||||||||||||
[flagged] | |||||||||||||||||
| ▲ | g42gregory 9 hours ago | parent | prev [-] | ||||||||||||||||
If you are trying to hack into a website, using a software tool (Claude Code in this case), you are breaking the law. It doesn’t matter if it’s a Claude Code or a text editor, you are the one responsible. And you are using a text editor in an “unsafe” manner. CC is not there to babysit anyone. | |||||||||||||||||
| |||||||||||||||||