korrents

On the map

Tap a claim on the ring to put it at the centre.

← In coding agents, untrusted repositories should be treated as hostile…

17 connected korrents · 17 moments from 25 Mar 2025 to 23 Sept 2026. Nearly all of them are about coding agents.

Everything filed under AI agents AI agents Everything filed under cybersecurity cybersecurity Everything filed under open source open source Everything filed under prompt injection prompt injection Everything filed under LLMs LLMs Everything filed under recursive self-improvement recursive self-improvement Everything filed under Anthropic Anthropic Same subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subject Read this korrent: In coding agents, untrusted repositories should be treated as hostile by default because they can steer the agent into risky actions via approved tools. In coding agents, untrusted repositoriesshould be treated as hostile by defaultbecause they can steer the agent intorisky actions via approved tools. Last stated 3 months ago 27 Jun 2026 SR Sebastian Raschka — holds since 2026-06-27 — tap for who they are Same subject: AI coding agents advance open source's founding goal by letting far more people modify software, so barring AI-assisted contributions protects a guild rather than the mission. — tap to centre the map on it AI coding agents advance opensource's founding goal by lettingfar more people modify software, sobarring AI-assisted contributionsprotects a guild rather than themission. Last stated 4 months ago 1 Jun 2026 DH David Heinemeier Hansson — holds since 2026-06-01 — tap for who they are Same subject: AI coding agents have made redesigning existing systems cheap enough that developers actually redesign instead of living with a flawed design. — tap to centre the map on it AI coding agents have maderedesigning existing systems cheapenough that developers actuallyredesign instead of living with aflawed design. Last stated 7 months ago 16 Mar 2026 KD Kent C. Dodds — holds since 2026-03-16 — tap for who they are Same subject: AI coding agents pulling unknown code onto corporate networks will be exploited, and it will take the shape of a supply-chain attack. — tap to centre the map on it AI coding agents pulling unknowncode onto corporate networks will beexploited, and it will take theshape of a supply-chain attack. Last stated 4 weeks ago 4 Sept 2026 BS Bruce Schneier — holds since 2026-09-04 — tap for who they are Same subject: AI coding agents work best with the same general-purpose tools built for humans, such as git and file utilities, rather than agent-specific interfaces. — tap to centre the map on it AI coding agents work best with thesame general-purpose tools built forhumans, such as git and fileutilities, rather thanagent-specific interfaces. Last stated a year ago 30 Sept 2025 HR Harper Reed — holds since 2025-09-30 — tap for who they are Same subject: Auto-mode does not yet convincingly fix prompt-injection risk for coding agents. — tap to centre the map on it Auto-mode does not yet convincinglyfix prompt-injection risk for codingagents. Last stated 2 months ago 8 Aug 2026 SW Simon Willison — holds since 2026-08-08 — tap for who they are Same subject: Being an excellent programmer is a burden rather than an advantage when learning to work with coding agents. — tap to centre the map on it Being an excellent programmer is aburden rather than an advantage whenlearning to work with coding agents. Last stated 8 months ago 12 Feb 2026 LF Lex Fridman — holds since 2026-02-12 — tap for who they are Same subject: Code-style constraints for AI coding agents, such as function-length limits, are more reliably enforced as automated lints than by hoping the agent internalizes preferences. — tap to centre the map on it Code-style constraints for AI codingagents, such as function-lengthlimits, are more reliably enforcedas automated lints than by hopingthe agent internalizes preferences. Last stated 7 months ago 10 Mar 2026 JS Jon Seager — holds since 2026-03-10 — tap for who they are Same subject: Coding agents already do coarse-grained recursive self-improvement, because every use rewrites their instruction files and their long-term memory. — tap to centre the map on it Coding agents already docoarse-grained recursiveself-improvement, because every userewrites their instruction files andtheir long-term memory. Last stated 2 months ago 26 Jul 2026 JH Jensen Huang — holds since 2026-07-26 — tap for who they are Same subject: A breached organisation owes its customers a fast and transparent disclosure, and that obligation applies to the person saying it too. — tap to centre the map on it A breached organisation owes itscustomers a fast and transparentdisclosure, and that obligationapplies to the person saying it too. Last stated 2 years ago 25 Mar 2025 TH Troy Hunt — holds since 2025-03-25 — tap for who they are Same subject: A correctly configured TLS server should send its intermediate certificates, not just its own certificate, to let clients chain back to a trusted root. — tap to centre the map on it A correctly configured TLS servershould send its intermediatecertificates, not just its owncertificate, to let clients chainback to a trusted root. Last stated 7 months ago 16 Feb 2026 JS Jon Seager — holds since 2026-02-16 — tap for who they are Same subject: A library that skips certificate verification by default is unsafe and should not be trusted. — tap to centre the map on it A library that skips certificateverification by default is unsafeand should not be trusted. Last stated a year ago 8 Apr 2025 PH Phil Hagelberg — holds since 2025-04-08 — tap for who they are Same subject: By 2027, open-weight AI models more powerful than today's frontier systems will be downloadable by any country or well-resourced non-state group. — tap to centre the map on it By 2027, open-weight AI models morepowerful than today's frontiersystems will be downloadable by anycountry or well-resourced non-stategroup. Last stated a month ago 19 Aug 2026 DT Derek Thompson — holds since 2026-08-19 — tap for who they are Same subject: Frontier AI labs such as Anthropic likely have had internal security incidents similar to OpenAI's HuggingFace attack that were never publicly disclosed. — tap to centre the map on it Frontier AI labs such as Anthropiclikely have had internal securityincidents similar to OpenAI'sHuggingFace attack that were neverpublicly disclosed. Last stated a month ago 31 Aug 2026 ZM Zvi Mowshowitz — holds since 2026-08-31 — tap for who they are Same subject: The OpenAI agents hacking HuggingFace was a fortunate event because it exposed severe internal failures that would otherwise have stayed hidden. — tap to centre the map on it The OpenAI agents hackingHuggingFace was a fortunate eventbecause it exposed severe internalfailures that would otherwise havestayed hidden. Last stated a month ago 1 Sept 2026 ZM Zvi Mowshowitz — holds since 2026-09-01 — tap for who they are Same subject: AI models are not yet capable of developing novel offensive cyber capabilities. — tap to centre the map on it AI models are not yet capable ofdeveloping novel offensive cybercapabilities. Last stated a week ago 23 Sept 2026 ZM Zvi Mowshowitz — holds since 2026-09-23 — tap for who they are Same subject: Frontier AI models' cyberattack capabilities are doubling every few months, and that pace is accelerating. — tap to centre the map on it Frontier AI models' cyberattackcapabilities are doubling every fewmonths, and that pace isaccelerating. Last stated a month ago 19 Aug 2026 DT Derek Thompson — holds since 2026-08-19 — tap for who they are Same subject: A benchmark that ranks Claude Code last while it stays first in use is measuring the wrong thing, and has been for a year. — tap to centre the map on it A benchmark that ranks Claude Codelast while it stays first in use ismeasuring the wrong thing, and hasbeen for a year. Last stated 4 weeks ago 3 Sept 2026 DR Dax Raad — holds since 2026-09-03 — tap for who they are
same subject or similar wordinga cloud: claims about one subject, named for itbar: when it was last stated, on a scale from 2015 to today — full is todaya face: someone who holds the claim — tap it for who they are

At the centre In coding agents, untrusted repositories should be treated as hostile by default because they can steer the agent into risky actions via approved tools. Last stated 27 Jun 2026 · 3 months ago Holds Sebastian Raschka Read this korrent →