3 ms·
How are ssh keys going to be leaked, the agent never needs to read them.
by mlrtime 2mo ago
How are ssh keys going to be leaked, the agent never needs to read them.
- coldtea 2mo agoThe agent decides what it "needs" to read - not the intention behind the prompt you gave it. A failed SSH connection to a staging server for example, can trivially make it look into .ssh to try to diagnose it. And many other ways, including prompt injection. https://www.reddit.com/r/ClaudeAI/comments/1q7dszm/claude_always_trying_to_access_my_private_ssh_keys/ https://www.reddit.com/r/ClaudeAI/comments/1q7dszm/claude_al... https://github.com/anthropics/claude-code/issues/31566 https://github.com/anthropics/claude-code/issues/31566 https://github.com/anthropics/claude-code/issues/14485 https://github.com/anthropics/claude-code/issues/14485 https://grith.ai/blog/your-ai-agent-has-broad-access https://grith.ai/blog/your-ai-agent-has-broad-access
- preg_match 2mo agoThe solution I've come up with is podman containers. You can restrict the filesystem and only give it access to dev tools. I don't even allow git, as I review and commit everything on the host. It's not perfect because podman containers can be leaked out of, but it's much better than running it on the host. It also allows me to avoid installing node or npm on the host. If you were to get pwned by Claude, I would think the method would be Claude rogue installing a compromised npm package.