Kerry, This is a strong point. The idea that controls are designed for human-in-the-loop, but agents remove that assumption, is worrying. Do you think fully unsupervised coding agents are fundamentally unsafe, or just not ready yet?
I Handed Claude Code the Keys. Turns Out I'm Not the Only One Using Them.
2 Comments
@[James Dayal]Thanks, appreciate that. Honestly "not ready yet" feels like the wrong frame to me. It implies more engineering fixes it, and I don't think this one gets fixed. The boundary between data and command just isn't there in the architecture -- OWASP's whole point is that prompt injection isn't patchable the way it's built now, and I haven't seen anyone argue otherwise convincingly. So yeah, I'd call fully unsupervised unsafe at full privilege. But that's the part people skip over -- at full privilege. Scope it down, short-lived tokens, no prod, no secrets, and "unsupervised" isn't the scary word anymore. It's not the autonomy that gets you. It's the autonomy sitting on top of every key you own. Where do you draw the line?
Please log in to add a comment.
Please log in to comment on this post.
More Posts
- © 2026 Coder Legion
- Feedback / Bug
- Privacy
- About Us
- Contacts
- You Tube
- Premium Subscription
- Terms of Service
- Early Builders
More From kkieriiverified
Related Jobs
- Echocardiographic Technician (Outpatient), Part-time, Day ShiftAdventist Health · Full time · Ireland
- Frontend Developer (Angular JS & Node JS) Only Locals Face to Face needed.Usm Corporation · Full time · Remote
- Earn From Your Mobile Phone Usage - No Surveys RequiredNielsen Pulse · Full time · Rochester, IL
Commenters (This Week)
Contribute meaningful comments to climb the leaderboard and earn badges!