|
|
|
|
|
by cjbprime
386 days ago
|
|
It's not that nonsensical. After it's accessed the private repo, it leaks its content back to the attacker via the public repo. But it's really just (more) indirect prompt injection, again. It affects every similar use of LLMs. |
|