← Back to context

Comment by otabdeveloper4

5 days ago

You can give the LLM a bash without giving it the full /usr/bin.

That's been a trivially solved problem for decades.

That has been one of the most common exploits for decades.

  • And as a result it is the most hardened.

    • So how do you explain it still being in the "OWASP Top 10" and the "CWE Top 25 Most Dangerous Software Weaknesses"?

  • Yes, and also MCP does literally nothing to prevent these sorts of exploits.

    Like I said, AI bros vibecoding slop because they literally have no clue what they're doing.