logoalt Hacker News

Leonard_of_Qtoday at 5:35 AM2 repliesview on HN

There's a clear solution to the danger posed to free software projects by accepting hostile submissions but it probably is not one that maintainers want to hear: they can use an agent to check submissions for nefarious patterns.

Sometimes you fight fire with fire.


Replies

m4rtinktoday at 11:44 AM

So next the attacker puts prompt injection in their PRs & take control of the agent on your end. Perfect, 10 out of 10.

show 1 reply
phoronixrlytoday at 5:45 AM

And sometimes you fight this by disabling PRs in Github, and do not put more water into LLM providers' wheel.