logoalt Hacker News

Iolaum • yesterday at 3:24 PM • 1 reply • view on HN

Nothing is stopping anyone from pointing their agent to that script to review and audit it before running it.


Replies

layer8 • yesterday at 3:27 PM

I don’t believe an agent can do that effectively without a sandbox to run the script in, if the script isn’t self-contained.

And everyone running a research agent on every download can’t be the solution. It’s much more effective to crowdsource a security database based on hashes. But for that, the downloads need to be self-contained.