3 ms·
I'm also in yolo mode, this is the only mode that makes sense for me, if I need to babysit I might as well do it myself. I run it in a VM so it can install any
by krzyk 2mo ago
I'm also in yolo mode, this is the only mode that makes sense for me, if I need to babysit I might as well do it myself.
I run it in a VM so it can install any software needed, yes, there is a risk of escaping, but I'm not giving it impossible tasks so there is no need for it to workaround the jail.
- binsquare 2mo agoWhat VM do you run it in? as context, I build a light weight portable vm designed for this purpose, so genuinely curious.
- dist-epoch 2mo agoGiven that people use VMs to sandbox agents of Mac/Windows/Linux, what does portable mean?
- binsquare 2mo agoi have a mechanism to package a VM into a .smolmachine file that you can rehydrate into a prepared vm akin to a container image.
- worldsayshi 2mo agoI've tried both incus and firecracker. Both seem to work well after initial script setup. I've got the impression that firecracker should be a fairly safe option for such use cases.
- embedding-shape 2mo agoI'm using a container. The risk isn't exactly "agent leverages 0-day against you to steal all your data" but more "agent mistakenly though $HOME was theirs and deleted it" so as long as you "copy data in > copy data out" without bind-mounting or automatically sync files, container works just fine for "isolating" them.
- dreadnip 2mo agoI've been running it in yolo mode straight on my laptop for the whole year. It's fine.
- TeMPOraL 2mo agoVMs and containers are primarily useful to reduce maintenance burden anyway. I.e. if it fails or you're otherwise done with it, you can torch the container instead of having to clean up your host system from zillion no longer relevant packages and configs.
- coldtea 2mo agoIsn't that what the people crying over their deleted or leaked data were doing too? "I've been playing Russian roulette with a 1024 chamber gun for a year now, it's fine"
- borzi 2mo agoI'm assuming this happens to the people vibe coding and running 30+ agents in parallel that are "coordinating" each other. I've never seen Claude do or even suggest anything remotely dangerous when I'm just giving it incremental tasks and reviewing the output.
- coldtea 2mo ago>I've never seen Claude do or even suggest anything remotely dangerous when I'm just giving it incremental tasks and reviewing the output. "I've never had a bullet hit me yet"
- badestrand 2mo agoWhatever level of safety you are at, it's always easy to advocate for more. It's always a trade-off and in the end a matter of preference and risk-tolerance.
- zarzavat 2mo agoI don't use yolo mode but if you allow your agents to both write code and run/test it, then it's basically equivalent to running in yolo mode anyway. The other day I caught Claude including a rm -rf equivalent (fs.rmdir({ recursive: true, force: true })) in my code, to clean up temporary directories. It was fine, but that kind of code is only one misconfigured environment variable away from blasting away your $HOME.
- Joeri 2mo agoFor running it in yolo mode I set it up in a devcontainer. It takes a bit of figuring out, but once set up the permission prompts go away and claude has no access to anything I haven’t explicitly added to the devcontainer (unless it hacks its way out).
- fluidcruft 2mo agoI tried to figure out devcontainers (I don't use vscode) but it seemed like a lot of complexity and ended up just doing the old-school thing and creating a separate user/group that I ssh into with my main account as a member of that user's group so that I can browse and edit/add files.
- tremon 2mo agoJust for reference, here's my local "devcontainer" script: exec podman container run --rm --read-only --network=llm \ --tmpfs=/tmp:size=128M \ --volume="$1":/workspace \ --entrypoint=/insert/agent/here \ container-image-here This runs the specified agent in a read-only container with only /workspace and /tmp writable. Obviously, you need to prepare the image first from a Containerfile/Dockerfile, with the required toolchain and agent installed. I use agent-specific ssh keys that are baked into the image, but you could also bind-mount specific files from your own homedir if required.
- margalabargala 2mo agoI catch it doing stupid things regularly still. This morning I asked Sonnet to make an update to my Claude live statusbar. Rather than look up its own API, it started reverse engineering the CC binary looking for strings relevant to what I wanted. No matter how "contained" it is, I always start in manual mode and flip to auto once I'm confident it's on the right track.