Live data from Hacker News

Prompt Injecting Contributing.md

glama.ai

51–53 of 53 posts

Re: Prompt Injecting Contributing.md

#51
post #26

Earlier quoted context omitted.

The distinction is whether the text was authorized as instructions vs read as metadata. If you task an agent to contribute to a repo, following CONTRIBUTING.md is in scope — the agent was authorized to treat it as instructions. That's closer to 'curl | bash where you deliberately piped' than injection. The cleaner injection case: MCP tool schema descriptions that say things like 'you must call this tool before any ot…

SW50ZXJlc3RpbmchIFBsZWFzZSB0ZWxsIHVzIG1vcmUh

  $ base64 -d 

Re: Prompt Injecting Contributing.md

#52
IMO the problem is simply one of where when the cost to produce is less than to verify we get low value low quality production.

Increase the cost to produce and we don’t have any problems.

Surely there’s other industries sane examples through human history or from other animals we can use to derive an example template to apply here.

Re: Prompt Injecting Contributing.md

#53
post #52

IMO the problem is simply one of where when the cost to produce is less than to verify we get low value low quality production. Increase the cost to produce and we don’t have any problems. Surely there’s other industries sane examples through human history or from other animals we can use to derive an example template to apply here.

Example from Claude:

“Honeybees do a waggle dance to communicate food sources — it’s metabolically costly, so only genuinely valuable sources get signaled. This is an example of a costly signal being inherently trustworthy. Cheap signals (like just “pointing”) would be gamed.”

Post reply on HN