|
|
|
|
|
by MadnessASAP
116 days ago
|
|
The threat model doesn't really change for agents that already have "web fetch" (or equivalent) enabled. The agent is free to communicate with untrusted websites[1]. As before, the firewall remains at what private information the agent is allowed to have. [1] If anything the threat gets somewhat reduced by the ability to point directly at a trusted domain and say "use this site and it's (presumably) trusted tools." |
|
But yeah, if you're already letting agents browse freely, the incremental risk might be smaller than I'm imagining.