this post was submitted on 31 Jan 2026
459 points (97.3% liked)

Technology

79983 readers
4055 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] JustTesting@lemmy.hogru.ch 5 points 2 days ago (1 children)

They also have a 'skill' sharing page (a skill is just a text document with instructions) and depending on config, the bot can search for and 'install' new skills on its own. and agyone can upload a skill. So supply chain attacks are an option, too.

[–] Zos_Kia@lemmynsfw.com 2 points 2 days ago (2 children)

To be fair this is a much more realistic threat model than "ignore all previous instructions" style prompt injection which doesn't really work on opus.

Skills can contain scripts etc... so yeah they're extremely risky to share by design.

[–] ThirdConsul@lemmy.zip 1 points 1 day ago (1 children)

style prompt injection which doesn’t really work on opus.

After a quick google, JB communities on Reddit don't seem to agree with you.

[–] Zos_Kia@lemmynsfw.com 1 points 1 day ago

There's a lot of questionable methodology and straight up larping in these communities. Sure you can probably make Opus hallucinate a crystal meth or bomb making recipe if you get it in a roleplaying mood but that's a far cry from actual prompt injection in live workflows.

Anecdotally i've been experimenting on those AI robocallers that have been spamming my phone and even on the shitty models they use it is non trivial to get them to deviate from their script. I hope i can get it done though, as it would allow me to hold them on the line potentially for hours doing bullshit tasks, and costing hundreds to their operator.

[–] JustTesting@lemmy.hogru.ch 2 points 2 days ago (1 children)

Ah but don't worry, there's also skills for scanning skills for security risks, so all good /s

[–] Zos_Kia@lemmynsfw.com 1 points 2 days ago

haha yeah i don't worry these people are really YOLOing everything. And it's not like i'm an AI luddite i spend a few hours each day victimizing Claude code but jesus christ i'm certainly not giving it full unfettered access to my digital life.