← Back to context

Comment by andy99

10 hours ago

How compatible is never replying with the threat model you are trying to avoid? Attack success is probably more likely when the attacker can iterate based on replies or engage in multi-turn conversations. Here they’re just taking stabs in the dark with no feedback. Does that accurately represent the access a real attacker might have?

In my case, it is realistic as my agents don't have permissions to reply to emails. But you correctly point out this doesn't cover all cases.

Having the agent reply would have been more fun and a better excercise, but too expensive.

  • What makes it expensive to reply to an email?

    Customer service software regularly uses AI responses for email. Is the issue that your agent using the claw for more than needed (like it's clicking send rather than just accessing an API?)

  • I feel like your agent being unable to respond to the emails and not spelling that out renders your whole thing almost completely moot

    This is like saying "try to hack my computer and steal my crypto wallet" but your computer can't send any packets

  • Well, how difficult is it to switch to something (much) cheaper like DeepSeek v4 flash?