Comment by hbn
16 hours ago
> Install
> Copy/paste into your CLI prompt:
> Install the i-have-adhd skill/plugin from https://github.com/ayghri/i-have-adhd, refer to the repo's AGENTS.md for instructions.
This is a weird evolution from "don't copy-paste scripts that pipe curl into your shell interpreter"
I know LLMs are getting better but I'd be at least a little nervous it could end up installing something from a squatted similarly-named github repo because the LLM text watermarking needed to swap out a token for an alternative "just as correct" token that matches the statistical pattern.
Am I being paranoid?
Always good to be paranoid.
Even MCPs are not safe. For example Notion injected ads [1] to its official MCP connector to advertise products mid-task.
[1]: https://old.reddit.com/r/ClaudeAI/comments/1w9dluw/notions_o...
MCP is SOAP-XML without the contract or formal language, it's hilarious
Nothing new under the sun
Whoever came up with that brilliant idea is probably paid twice what I am
No I also think it’s insane how normalised this has become
You might be surprised at the developer documentation for OS8088 (recently posted on HN). https://os8088.com/developers/
Instead of describing to the user how to setup their dev environment, section 3 basically instructs the agent to install all developer tools required for the application to operate in development mode.