註冊並分享邀請連結,可獲得影片播放與邀請獎勵。

Drew Breunig
@dbreunig
Writing about and working on AI, DSPy, geo, and data.
加入 March 2008
1.2K 正在關注    9.5K 粉絲
Was reminded about this again today and it still blows my mind.
TIL Claude Code allows Skills to run commands to inject content. This behavior is enabled by default, runs silently, & doesn't require user approval. There are some guardrails, but I was able to inject a .env file with no complaints! 🤯 drskill has been updated to guard against this avenue of exploits:
顯示更多