Hacker News new | ask | show | jobs
by freeone3000 432 days ago
What if we started the other way, by explicitly declaring what files an LLM process was capable of accessing? a snap container or a chroot might be a good first attempt