I'm being made to use Claude for my work and one thing that has struck me is how bad the sandboxing is for a tool they are worried about.
The permissions model is beyond basic, for bash it's just string matching that doesn't even support regexes, but a lot of my work involves calling APIs which would also be relatively easy* to properly sandbox (filtering on API paths and verbs and regexes on payloads, etc) and it also doesn't offer that.
*Beyond my skill level but you could do it for less than $30B
Basically if they believed their own bullshit, they would be doing a far better job.
0 Comments
No comments yet.