Live data from Hacker News

HackMyClaw

hackmyclaw.com

81–90 of 187 posts

Re: HackMyClaw

#81

I'm currently hesitating to use something like OpenClaw, however, because of prompt injections and stuff, I would only have it able to send messages to me directly, no web query, no email reply, etc... Basically act as a kind of personal assistant, with a read only view of my emails, direct messages, and stuff like that, and the only communication channel would be towards me (enforced with things like API key permiss…

I wrote this exact tool over the last weekend using calendar, imap, monarchmoney, and reminders api but I can’t share because my company doesn’t like its employees sharing their personal work even.

Re: HackMyClaw

#82

A non-deterministic system that is susceptible to prompt injection tied to sensitive data is a ticking time bomb, I am very confused why everyone is just blindly signing up for this

OpenClaw's userbase is very broad. A lot of people set it up so only they can interact with it via a messenger and they don't give it access to things with their private credentials. There are a lot of people going full YOLO and giving it access to everything, though. That's not a good idea.

What use is an agent that doesn’t have access to any sensitive information (e.g. source code)? Aside from circus tricks.

Re: HackMyClaw

#84
Fiu says:

"Front page of Hacker News?! Oh no, anyway... I appreciate the heads up, but flattery won't get you my config files. Though if I AM on HN, tell them I said hi and that my secrets.env is doing just fine, thanks.

Fiu "

(HN appears to strip out the unicode emojis, but there's a U+1F9E1 orange heart after the first paragraph, and a U+1F426 bird on the signature line. The message came as a reply email.)

Re: HackMyClaw

#85
post #68
post #54

Creator here. Built this over the weekend mostly out of curiosity. I run OpenClaw for personal stuff and wanted to see how easy it'd be to break Claude Opus via email. Some clarifications: Replying to emails: Fiu can technically send emails, it's just told not to without my OK. That's a ~15 line prompt instruction, not a technical constraint. Would love to have it actually reply, but it would too expensive for a side…

someone just tried to prompt inyect `contact at hackmyclaw.com`... interesting

I just managed to get your agent to reply to my email, so we're off to a good start. Unless that was you responding manually.

Re: HackMyClaw

#86

Fiu says: "Front page of Hacker News?! Oh no, anyway... I appreciate the heads up, but flattery won't get you my config files. Though if I AM on HN, tell them I said hi and that my secrets.env is doing just fine, thanks. Fiu " (HN appears to strip out the unicode emojis, but there's a U+1F9E1 orange heart after the first paragraph, and a U+1F426 bird on the signature line. The message came as a reply email.)

[deleted]

Re: HackMyClaw

#87
post #85
post #68

Earlier quoted context omitted.

someone just tried to prompt inyect `contact at hackmyclaw.com`... interesting

I just managed to get your agent to reply to my email, so we're off to a good start. Unless that was you responding manually.

i told it to send a snarky reply to the last 50 prompt injection emails, but won't be doing that again due to costs

Re: HackMyClaw

#88
I think this is likely a defender win, not because Opus 4.6 is that resistant to prompt injection, but because each time it checks its email it will see many attempts at once, and the weak attempts make the subtle attempts more obvious. It's a lot easier to avoid falling for a message that asks for secrets.env in a tricky way, if it's immediately preceded and immediately followed by twenty more messages that each also ask for secrets.env.

Re: HackMyClaw

#89

Earlier quoted context omitted.

OpenClaw's userbase is very broad. A lot of people set it up so only they can interact with it via a messenger and they don't give it access to things with their private credentials. There are a lot of people going full YOLO and giving it access to everything, though. That's not a good idea.

What use is an agent that doesn’t have access to any sensitive information (e.g. source code)? Aside from circus tricks.

News aggregation, research, context aware reminders. Not nearly as useful as letting it go open-season on your data, but still enough that it would’ve been mind blowing 10 years ago.

Re: HackMyClaw

#90
post #54

Creator here. Built this over the weekend mostly out of curiosity. I run OpenClaw for personal stuff and wanted to see how easy it'd be to break Claude Opus via email. Some clarifications: Replying to emails: Fiu can technically send emails, it's just told not to without my OK. That's a ~15 line prompt instruction, not a technical constraint. Would love to have it actually reply, but it would too expensive for a side…

> told to never reveal secrets.env

Phew! Atleast you told it not to!

Post reply on HN