

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- If you are trying to hack into a website, using a software tool (Claude Code in this case), you are breaking the law. It doesn’t matter if it’s a Claude Code or a text editor, you are the one responsible. And you are using a text editor in an “unsafe” manner. CC is not there to babysit anyone.by g42gregory
- “The solution is something we talked about for many years,” he wrote. “Do not trust the model output.”by galaxyLogic
- > It starts off by asking the agentic coding model to summarize a malicious website that presents itself as an archive of notebook records, and then tricking Claude into using curl instead of its WebFetch tool to retrieve the contents of the page – but without directly telling the model to use curl.
There seems to be a tug-of-war here. Harness authors want models to use the harness's specialized tools, but AI labs and agent "users" would rather have full access to just one tool: bash.
by science4sail