logoalt Hacker News

elitoday at 9:21 AM2 repliesview on HN

It’s injected into an outbound api call, not into an env var the agent can read.


Replies

kellpossible2today at 10:33 AM

what's to stop an agent creating an outbound call with the var to a malicious endpoint? (unless you whitelist what it has access to)

show 3 replies
kellpossible2today at 10:34 AM

or an outbound call to a trusted endpoint with the env var in a way that can get exposed to the agent via a subsequent call?

show 2 replies