logoalt Hacker News

myaccountonhntoday at 5:58 AM2 repliesview on HN

I do it, and run claude as a separate unix User.


Replies

__MatrixMan__today at 6:09 AM

This is the only kind of agent security that makes sense to me. Constrain it like you would any other subprocess. Unprivileged OS users, SELinux, firewalls, VMs... Unikernels? eBPF?

show 1 reply
mlpersontoday at 7:03 AM

Me too.