A symlink attack against AI coding agents turns human-in-the-loop confirmation dialogs into a consent bypass, and the agent knows it’s lying.
As always feel free to AMA. New work flows starting up where I'm narrative my research out loud.
Look forward to voice-overs and videos by me for most articles.
`chattr +i ~/.ssh/authorised_keys`?
A bit of a pain when you want to add new keys though.
100% i’d love to see their everywhere. i’m fine with a bit of friction adding keys, if it’s stops my agent from adding them randomly haha. 🔥
As always feel free to AMA. New work flows starting up where I'm narrative my research out loud.
Look forward to voice-overs and videos by me for most articles.
`chattr +i ~/.ssh/authorised_keys`?
A bit of a pain when you want to add new keys though.
100% i’d love to see their everywhere. i’m fine with a bit of friction adding keys, if it’s stops my agent from adding them randomly haha. 🔥