๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Drew Breunig
@dbreunig
Writing about and working on AI, DSPy, geo, and data.
๊ฐ€์ž… March 2008
1.2K ํŒ”๋กœ์ž‰ ์ค‘    9.5K ํŒฌ
TIL Claude Code allows Skills to run commands to inject content. This behavior is enabled by default, runs silently, & doesn't require user approval. There are some guardrails, but I was able to inject a .env file with no complaints! ๐Ÿคฏ drskill has been updated to guard against this avenue of exploits:
๋” ๋ณด๊ธฐ