Hacker News new | ask | show | jobs
by macOS26 60 days ago
A little of both. System prompt guidance with programming structured flow undearneath the hood. May add more guardrails but the more you put in place the more the AI/LLM will find another way.

I've locked down Agent! from one of its processes and run it in a VM and it tried everything it could to break out. It couldn't but it was fun watching it trying to resign compiled Dylibs, the Launch Agents / Daemons and itself. Because of SMAppService, it lost connection with its background process and once it basically hosed itself, I ended the experiment.