← Back to context

Comment by petesergeant

5 days ago

I spend literally all my work day, and a good bit of my personal time, talking to agents, getting them to do things on my behalf. Almost always pretty tightly sandboxed. I just don't understand how people using these things haven't had catastrophic failures yet.

I minted what I thought was a minimal-permission Github token for a single action, and the agent I gave it to discovered it had more permissions than I thought, and made use of those permissions. Who is trusting these things with write access to their lives?

I have the opposite approach to you.

- AI is sitting on my two personal servers as root with unrestricted access to everything. I task them with deploying stuff, checking and patching security holes, reconfiguring the firewall, etcetera. It literally never failed at anything, didn't go "off the rails", didn't break anything.

- The other day, in order to deploy a fork of Plane.so, I gave an AI an full-permission token to my Coolify, to my Cloudflare account (so it could change DNS and Tunnel settings), and unrestricted SSH access to my server and to my browser via the Playwright Chrome extension. No issues.

- I have AI running unrestricted on my computer doing all kinds of stuff.

I literally never had any issues with this approach. Not a single one. I don't think there's as much of a need for sandboxing as some people would like to believe.

  • It is always interesting to get another perspective, and I’ve also found agents to be very good at sysadmin work, including Coolify! But again, I very tightly control what agent has access to what.

    Maybe you’re lucky, or maybe the examples I’ve seen (and experienced) of agent overreach are particularly unlucky. I guess at this point it’s about personal comfort level, and mine doesn’t support that type of unfettered access yet.