> examples of systems that take an LLM and give it the ability to trigger additional tools—...execute generated code in an interpreter or a shell. As a security person... oh, no no no no. Glad i dont have to secure that. Black box we don't really understand executing shell scripts in response to untrusted user input. Has a scarier sentence ever been spoken in the history of computer security?
Yeah, I'm also in computer security, and watching the incredibly dumb ways people are using LLMs has made me absolutely terrified. Like, I had somehow very-incorrectly thought that if an AI wanted to do something bad it would have to trick a human into helping it have agency... it never occurred to me that developers would just happily sit around excitedly wiring up AI directly to shells and database query languages…
And wire the other side to the open internet!