Hacker News new | ask | show | jobs
by rcxdude 162 days ago
Part of the issue is reads can exfiltrate data as well (just stuff it into a request url). You need to also restrict what online information the agent can read, which makes it a lot less useful.