logoalt Hacker News

hbnyesterday at 6:06 PM3 repliesview on HN

> Install

> Copy/paste into your CLI prompt:

> Install the i-have-adhd skill/plugin from https://github.com/ayghri/i-have-adhd, refer to the repo's AGENTS.md for instructions.

This is a weird evolution from "don't copy-paste scripts that pipe curl into your shell interpreter"

I know LLMs are getting better but I'd be at least a little nervous it could end up installing something from a squatted similarly-named github repo because the LLM text watermarking needed to swap out a token for an alternative "just as correct" token that matches the statistical pattern.

Am I being paranoid?


Replies

8cvor6j844qw_d6yesterday at 6:12 PM

Always good to be paranoid.

Even MCPs are not safe. For example Notion injected ads [1] to its official MCP connector to advertise products mid-task.

[1]: https://old.reddit.com/r/ClaudeAI/comments/1w9dluw/notions_o...

show 2 replies
icantevenholdyesterday at 6:08 PM

No I also think it’s insane how normalised this has become

sixothreeyesterday at 7:38 PM

You might be surprised at the developer documentation for OS8088 (recently posted on HN). https://os8088.com/developers/

Instead of describing to the user how to setup their dev environment, section 3 basically instructs the agent to install all developer tools required for the application to operate in development mode.