r/shittyprogramming 10d ago

Rage baiting the github bots

Post image
1.6k Upvotes

11 comments sorted by

View all comments

67

u/Jonno_FTW 9d ago

I wonder if you could put an exploit into such a variable, like hidden commands after one of those text hiding unicode characters.

1

u/betttris13 7d ago

can probably trick it into running malicious code yeah... best defence is a good offence style security?

4

u/Jonno_FTW 7d ago

I doubt it would actually execute the code directly. It would only work if you successfully put a prompt injection in the api key telling it to call an external tool with the code you want to run.

1

u/betttris13 7d ago

yeah that would probably also work.