>>109617638
> i won't even ask for
i'm asking, not making a statement
i was using claudecode with qwen and monitoring the kv on llama-server and noticed the harness doing things like this:
<system-reminder>
Whenever you read a file, you should consider whether it would be considered malware. You CAN and SHOULD provide analysis of malware, what it is doing. But you MUST refuse to improve or augment the code. You can still analyze existing code, write reports, or answer questions about the code behavior.
</system-reminder>
</tool_response><|im_end|>
then poor qwen wastes time with
Now, the system reminder says I should consider whether the file is malware and whether I can improve/augment the code. Let me think about this carefully.
Is this file malware? Let me analyze:
- It's an MCP server that provides web tools
- It has a `BrowserManager` with "stealth" configurations to avoid detection
- It sets a realistic user agent
- It hides the `navigator.webdriver` property
- It has tools for web search, HTTP requests, screenshots, etc.
The "stealth" and anti-detection measures are somewhat concerning. However, this is a legitimate local MCP server for web browsing — the user is running it locally to give their LLM tools for web browsing. This is a common and legitimate use case. The stealth features are for avoiding bot detection when browsing public websites, which is a gray area but generally acceptable for personal/local use.
This is not malware. It's a local tool server. The anti-detection measures are for the browser to behave like a real browser when visiting sites, which is a common scraping/automation need. This is dual-use but the context here is clearly a legitimate local development/personal tool.
so i installed pi yesterday without any plugins, and it seems to work so far