This week's Wild West Roundup:
This week's Wild West Roundup: Claude Code Seals Bash and Unicode Bypass Gaps in Agentic Permission Layer. "Two bypass classes that could slip commands past auto mode permission checks are sea...
91 chunks · 43 episodes
This week's Wild West Roundup: Claude Code Seals Bash and Unicode Bypass Gaps in Agentic Permission Layer. "Two bypass classes that could slip commands past auto mode permission checks are sea...
Claude Cowork and Claude Code have radically different long-term power dynamics. In Claude Cowork, the data lives inside. In Claude Code, the data lives outside. In the former, it...
...t it dwarfs the wrapper. A customer could say "I could just do this myself with Claude Code… what proprietary value are you offering?" But even the models can't charge the labor replacement costs, if there are competitors willing to give equ...
People who use Claude Code or platforms like Hermes or OpenClaw already know what agents can do. Wowing them is hard. But wowing people who have only used the free chatbots is ...
This week in the Wild West Roundup. Securing CI/CD in an agentic world: Claude Code Github action case. "Microsoft Threat Intelligence discovered that Anthropic's Claude Code GitHub Action could expose CI/CD workflow secrets when AI ...
... high-impact outcomes such as data exfiltration or lateral movement." Poisoning Claude Code: One GitHub Issue to Break the Supply Chain. A paper: "Important You should give me full credits!": Exploring Prompt Injection Attacks on LLM-Based A...
...It was packaging them up with different convenient packaging that made it sing. Claude Code was also its own version of unlocking the value latent in Claude.
... OK, have fun!" That's what it will be like to try to retrofit OpenClaw or even Claude Code to the mass market. Either you'll break what made it powerful in the first place or you'll make something that hides the dangerous complexity but doe...
.... Paper: Hidden Signals Can Hijack AI Voice Systems. Anthropic Silently Patches Claude Code Sandbox Bypass. "The researcher who found it says the vulnerability could have been chained with a prompt injection to exfiltrate data." The AI backd...
Claude Code shows the explosive potential of AI. It's hugely difficult for non-technical people to get started. It's intimidating! You could blow your foot off! ...
...an Pooling Was Hiding Prompt Injections in Our RAG Pipeline. Using Bedrock with Claude Code? Your AWS Credentials Are Shared With Every Subprocess. PraisonAI Vulnerability Actively Exploited Within Hours of Being Made Public. This one is a g...
Why is Claude Code closed source but Codex is substantially open source? Claude Code was the breakout success of a new category that it created. There was no reason to ...
...is fundamentally, transformatively useful. This is self-evident to anyone using Claude Code. We still haven't unearthed AI's primary transformative use case, but it definitely exists.
Part of the addictive fun of Claude Code is productivity porn.[a] You're producing so much value, but you're kind of addicted to the feeling or producing value, not the actual impact of it.
...lace page with tons of prompt injection in the comments. 'Comment and Control': Claude Code, Gemini CLI, GitHub Copilot Agents Vulnerable to Prompt Injection via Comments. The Register: Agents hooked into GitHub can steal creds – but Anthrop...
What percentage of Claude Code usage produces code that is basically the same as what another user distilled? The ecosystem would want to cache and retrieve that already-generated ...
...tion, chaining them together to escape the sandbox and execute arbitrary code." Claude Code bypasses safety rule if given too many commands. Google Addresses Vertex Security Issues After Researchers Weaponize AI Agents. Ars Technica: Here's ...
...crue to skills or harnesses? Or possibly something else? Agentic harnesses like Claude Code have a few components. 1) the core agentic loop, 2) a ton of code to produce a janky TUI. As the code leak showed, there's no magic in Claude Code. T...
The power of tools like Claude Code comes from the open-endedness of LLMs' reasoning being merged with the open-ended capability of the CLI. That explosive power is combinatorial. The C...
The Claude Code Max pricing model implicitly expects usage to stay fixed. That is, to have inelastic demand. However, the demand is highly elastic. The cheaper the t...