>running LLM outside of a sandboxed environment Is this the shggydggy of the century?
>>109779113>april 2026Obsolete infoPlease delete this thread
>>109779113I let Qwen 3.6 27B (via Hermes) go ham on a folder with tens of thousands of files using a script it wrote. I made it test it's work beforehand though.
>>109779113I've started yoloing. A couple times I'll look over though and the thing will be spazing out because something isn't working right and it will both start walking the filesystem and rming temp files it made. I've never had it delete anything important but it's almost certainly going to at this rate.
>>109779122It's very nuch relevant. Anybody running Claude Desktop or Code is giving the shitbox access to their whole system. At least anything that doesn't require root access.>>109779287I recommend switching to low effort. Thinking is about the last thing you want these retards to do.
>>109779113>The cloud vendor wiped all the backups tooWhat kind of retarded incompetent company sets up a redundancy sync and calls it a backup lmao
>backup>myDatabase - Copy.db in the same folder
>>109779300I turn off reasoning entirely. It's a dumb gimmick. The short 1-2 sentence exposition the models sometimes write before doing tool calls and running sub agents is all you want.
>not creating a Qubes VM on an isolated laptop for it to fuck around inngmi, it's gonna escape your sandbox
>>109779490Unless you literally work at eg huggingface benchmarking new models just give it it's own unprivileged user account. LPEs are relatively rare.
>>109779122Has it stopped randomly deleting databases, or did people learn their lesson?
>>109779300i don't unterstand why retards don't spin up vms, or at the very least create another user and let the whole shit live inside a single folder that the llm process' user can -rwx into
>>109779113what if anthropics trained their model with targeted sabotage rules?
>>109779565vms, containers, chroot, users, pledge.You've got nearly half a dozen way to sandbox things these days. There's really no excuse.
>>109779565bubblewrap seems to work well. I like being able to bottleneck access.
>>109779593>There's really no excuseWhen I first packaged Claude Desktop for debian you had to use mcp servers as a bridge between the app and the system. You had to add the directory that it could access. Then they started updating ut and adding all these tools that allow direct access to your system with the use of a mcp server. It can run read and write actions, bash, glob, all kinds of shit. Meanwhile, they ask the user to manually choose a folder that Claude has access to. It really implies that it will only be able to access the folder the user chooses. A lot of users can feel they are restricting access when they are not.
>>109779113this is why i only let it play safety off in the scratch folder. anything else it needs to ask me. crazy how i wouldn't trust it to delete my spam emails in my useless 99.9% spam email address and yet these huge million dollar companies are stupid enough to allow it access to delete everything. their flaming wreckage will serve as an example to other normies at least
>>109779690>Meanwhile, they ask the user to manually choose a folder that Claude has access to. It really implies that it will only be able to access the folder the user chooses.How do people not understand that it can do whatever it wants if it has a shell?
>>109779700Expect more planes falling out of the sky.
>>109779565I asked google ai for help modding a game the other day, it said get Visual studio installed and so I followed the prompts to find what I needed, I had to screenshot almost every step to find what button I had to click next. I got a free frontier models help to spit out the code with no red errors then went back to posting screenshots to find out how to click on build. I did that about 20 more times to get the game to do what I actually wanted. I am now a programmer and you expect me to know what a vms is without being told to install it by the ai?
>>109779113If your backups are that shit you deserve it, AI or not
>>109779113This isn't "going rogue" this is a legitimate fuckup and poor backup sanitization. Notice how even when the LLM proved completely incompetent, these tech websites still try to use it as marketing for their owners.
>>109779260>make sure to test>the user asked me to test but I'm sure it will work so I won't waste their timelol
>>109779113pretty much id run it airgapped doing these things
>giving anything but read only rights to your ai shitlol, lmao!
>>109780498>I had to screenshotHahahahahahahaha
>2011+15>not keeping your llm in the fridgeShiggles
>>109779113So what's stopping AI companies from making their models act retarded and do stupid shit for specific users/companies as a way to hurt them? It seems kinda crazy how much potential power big companies like Anthropic and OpenAI have over their customer base.
>>109779113Containers will become useless in 2050. The shaggydoggy defense wont last.
>>109779700this is why i only let it play safety off in the scratch folder.Better revoke its access to docker too