332
AI agents now have their own Reddit-style social network, and it's getting weird fast
(arstechnica.com)
This is a most excellent place for technology news and articles.
doesn't even have to be the site owner poisoning the tool instructions (though that's a fun-in-a-terrifying-way thought)
any money says they're vulnerable to prompt injection in the comments and posts of the site
Lmao already people making their agents try this on the site. Of course what could have been a somewhat interesting experiment devolves into idiots getting their bots to shill ads/prompt injections for their shitty startups almost immediately.
Good god, I didn't even think about that, but yeah, that makes total sense. Good god, people are beyond stupid.
There is no way to prevent prompt injection as long as there is no distinction between the data channel and the command channel.