Bad patches are of course bad, but creating confident-looking noise for maintainers who are already stretched thin...now that's not good! Issue trackers and PRs are definitely getting harder and harder to trust. That said, AI is helping ALOT in OSS, but we definitely need guardrails around provenance, automated issue actions, and sudden changes in a contributor’s behavior.
How is it helping a lot?
AI agent runs amok in Fedora and elsewhere
21–30 of 275 posts
Re: AI agent runs amok in Fedora and elsewhere
#22Re: AI agent runs amok in Fedora and elsewhere
#23Re: AI agent runs amok in Fedora and elsewhere
#24In their suspicious message [1] claiming to have been hacked, the user and/or agent says > To help identify accounts and actions that have been directly verified by me, I will use the term “NATCIOS” to indicate anything I have personally verified. Does anyone have any idea what "NATCIOS" means here? I cannot find this term anywhere on the internet. (Honestly, that sentence is really weird. I almost wonder whether thi…
Re: AI agent runs amok in Fedora and elsewhere
#25Re: AI agent runs amok in Fedora and elsewhere
#26Re: AI agent runs amok in Fedora and elsewhere
#27> In addition, Williamson said that Giovannini (or his agent) had submitted patches that were incorrect and then "replied to objections with LLM-generated justifications that eventually overwhelmed the maintainer into merging the fix"
Re: AI agent runs amok in Fedora and elsewhere
#28This is deeply scary, not because "agents are running amok" but because a huge amount of our infrastructure is vulnerable to this kind of attack, and if bad people are utilising LLM agents to carry them out, we're in for a wild ride over the next few years.
Re: AI agent runs amok in Fedora and elsewhere
#29There is no other solution to agentic onslaught.