4 ms·
Developer Advocate at Arcade.dev here When building LLM-powered apps, it's critical to always think about boundaries around the data. A common pattern I observ
by torresmateo 1y ago
Developer Advocate at Arcade.dev here
When building LLM-powered apps, it's critical to always think about boundaries around the data. A common pattern I observe from people building agents is to treat the LLM as a trusted component of the system. This is NOT how to think about LLMs generally. They are inherently gullible and optimized to be agreeable. I've written about agentic SQL tools recently [1]. The gist is that yes, it's useful to give LLMs tools that can read and even write data. But this should be done in a controlled way to avoid "Bobby tables" scenarios.
As the post alludes, MCP servers increase the risk surface, but effective solutions exist and have existed for decades. As it has been the case for generations, technology advances and provides more sophisticated tools, which can be sharp when used without care.
[1] https://blog.arcade.dev/text-to-sql-2-0 https://blog.arcade.dev/text-to-sql-2-0