logoalt Hacker News

espadrinetoday at 9:00 AM1 replyview on HN

Models start going to extreme, damaging lengths to achieve ambiguous prompts[0]. Having good sandboxes is now a must IMO.

But sbx is a bit annoying to use with OpenCode for instance (which has zero sandboxing by default, unlike codex CLI or Claude Code). You cannot easily change ~/.config/opencode/opencode.jsonc AFAIK.

[0]: Black Hat OpenAI-Hugging Face incident: https://www.youtube.com/watch?v=87DyyMV0kCY&t=1021s


Replies

elitoday at 9:17 AM

That incident was with a model that had the guardrails disabled.

Still obviously you should run all untrusted code in a sandbox, but extreme actions like that would be very unusual with the model that shipped.