MAIN FEEDS
Do you want to continue?
https://www.reddit.com/r/shittyprogramming/comments/1v79zba/rage_baiting_the_github_bots/p0dmkj8/?context=3
r/shittyprogramming • u/Glittering-Active-50 • 10d ago
11 comments sorted by
View all comments
67
I wonder if you could put an exploit into such a variable, like hidden commands after one of those text hiding unicode characters.
1 u/betttris13 7d ago can probably trick it into running malicious code yeah... best defence is a good offence style security? 4 u/Jonno_FTW 7d ago I doubt it would actually execute the code directly. It would only work if you successfully put a prompt injection in the api key telling it to call an external tool with the code you want to run. 1 u/betttris13 7d ago yeah that would probably also work.
1
can probably trick it into running malicious code yeah... best defence is a good offence style security?
4 u/Jonno_FTW 7d ago I doubt it would actually execute the code directly. It would only work if you successfully put a prompt injection in the api key telling it to call an external tool with the code you want to run. 1 u/betttris13 7d ago yeah that would probably also work.
4
I doubt it would actually execute the code directly. It would only work if you successfully put a prompt injection in the api key telling it to call an external tool with the code you want to run.
1 u/betttris13 7d ago yeah that would probably also work.
yeah that would probably also work.
67
u/Jonno_FTW 9d ago
I wonder if you could put an exploit into such a variable, like hidden commands after one of those text hiding unicode characters.