At this stage with the latest models with "increased persistence" and the sheer amount of supply chain attacks, you'd be insane not running these tools in a sandbox.
Yet millions do just that without any widely reported issues yet.
For supply chain attacks, there has not been a comprehensive solution, if for example you have to use a number of npm dependencies.
No one has the capacity to review changes to these dependencies when you upgrade them.
Now, if only we had an automatic tool that could intelligently review a large amount of code changes for malicious or vulnerable additions...
Exactly. Claude in a VM is the way to go.
Yet millions do just that without any widely reported issues yet.
For supply chain attacks, there has not been a comprehensive solution, if for example you have to use a number of npm dependencies.
No one has the capacity to review changes to these dependencies when you upgrade them.
Now, if only we had an automatic tool that could intelligently review a large amount of code changes for malicious or vulnerable additions...