← Back to context

Comment by order-matters

4 hours ago

the argument to be made is that allowing anthropic to see it constitutes sending the threat.

sandbox your ai.

That is not what sandboxing solves. A good sandbox would inject credentials into provider API calls so that the model never sees credentials, but the provider is still going to see the transcript. Sandboxes do not require or imply that there is a local model. Sandboxes limit what the agent can access on the host machine as well as the network and public internet.

  • >Sandboxes limit what the agent can access on the host machine as well as the network and public internet.

    this is exactly what I meant. I am presuming the danger is AI reacting to personal notes that it reads on your computer, like a diary, and you should not allow the tools to have access to those documents.

how does sandbox help in this case when you use a provider like anthropic/openai?

  • Another way to interpret this is that they are legally presuming that you already have sandboxed their product and anything it sees or has access to is intentional.

    Any failure to understand what it can access or what it has permission to see from the user's end is presumably not their problem. Regardless of what the user specifically asks of the tool.

  • If you're still using a provider like this then you didn't sandbox the AI. You still need to follow the instruction.