Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bettaher_adam
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
bettaher_adam
6mo ago
The fail-closed approach is the right default. One thing I'd add to the attack classes you're considering: prompt injection via filesystem reads — an attacker can craft a file that, when read by the agent, injects instructions
2.
▲
by
bettaher_adam
6mo ago
The skeptic loop concept is the most interesting part here. One thing worth considering for the validation layer: signing the intermediate outputs between agents with HMAC so you can trace exactly which agent in the chain produced which
3.
▲
by
bettaher_adam
6mo ago
Interesting approach to knowledge unit validation. One thing I've noticed when building constrained LLM pipelines: separating the system prompt from user input at the message level (not string concatenation) makes a significant dif