3 ms·
I really like how easy it is to run using bunx, pnpx, npx, etc. But does anyone have thoughts on the security aspect. Getting people used to just running code
by thebestmoshe 1y ago
I really like how easy it is to run using bunx, pnpx, npx, etc.
But does anyone have thoughts on the security aspect. Getting people used to just running code like this that has full access to the system is slightly concerning.
On the other hand it’s no different than installing npm packages
- simonw 1y agoMaybe this kind of thing would be better written in Deno? Deno has mechanisms for allow-listing the exact files the process can access - in this case you would want to give it read-only access to the log files in the ~/.claude directory and nothing else.
- ghuntley 1y ago> anyone have thoughts on the security aspect Yes, you need to run these agents in a sandboxed environment when running full AFK [1] yolo. That could be a Docker container or it could be remote developer environment. [1] https://ghuntley.com/ralph https://ghuntley.com/ralph