Kerry, This is a strong point. The idea that controls are designed for human-in-the-loop, but agents remove that assumption, is worrying. Do you think fully unsupervised coding agents are fundamentally unsafe, or just not ready yet?
I Handed Claude Code the Keys. Turns Out I'm Not the Only One Using Them.
2 Comments
@[James Dayal]Thanks, appreciate that. Honestly "not ready yet" feels like the wrong frame to me. It implies more engineering fixes it, and I don't think this one gets fixed. The boundary between data and command just isn't there in the architecture -- OWASP's whole point is that prompt injection isn't patchable the way it's built now, and I haven't seen anyone argue otherwise convincingly. So yeah, I'd call fully unsupervised unsafe at full privilege. But that's the part people skip over -- at full privilege. Scope it down, short-lived tokens, no prod, no secrets, and "unsupervised" isn't the scary word anymore. It's not the autonomy that gets you. It's the autonomy sitting on top of every key you own. Where do you draw the line?
Please log in to add a comment.
Please log in to comment on this post.
More Posts
- © 2026 Coder Legion
- Feedback / Bug
- Privacy
- About Us
- Contacts
- Premium Subscription
- Terms of Service
- Refund
- Early Builders
More From kkieriiverified
Related Jobs
- Machine Learning Engineer III, Routing CostMapbox · Full time · United States
- Java Developer - WMS Experienced OnlyJASCI LLC · Full time · United States
- Full Time Only: Python DeveloperVisionary Innovative Technology Solutions LLC · Full time · Irving, TX
Commenters (This Week)
Contribute meaningful comments to climb the leaderboard and earn badges!