Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
agentictrustkit
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
agentictrustkit
4mo ago
Yeah I don't think enough people talk about this. AI makes your existing process faster, but it doesn't make a broken process correct. We've seen this at every inflection point — cloud, agile, microservices, now AI. My bet is
2.
▲
by
agentictrustkit
6mo ago
The “LLMs don’t have responsibility” point is exactly why the interface matters. I as a person can be held to norms like not to run unknown code, but a model can't internalize that so you need the system to make the safe path the defau
3.
▲
by
agentictrustkit
6mo ago
One thing that jumps out in these incidents is how quickly we shift from "package integrituy" to "operator integrity." Once an LLM is in the loop (even as a helper0, its effectevly acting as an operator that can influenc
4.
▲
by
agentictrustkit
6mo ago
One downstream effect of "agents can publish code" is that the trust signals weve relied on for years (stars, maintainer reputation, issue history...etc) got noisier. I don't think that means the ecosystem collapses, but it c
5.
▲
by
agentictrustkit
6mo ago
This is how I've come to think about it. It's less a "clever string that bypasses prompts" and more "untrusted parties are participating in your control plane." That's why purely linguistic defenses feel u
6.
▲
by
agentictrustkit
6mo ago
I like that everyone keeps separating "capability" from "authority" because they get conflated in a lot of agent-centered tooling. CLI vs MCP choice mostly changes the HOW as a side effect. It doesn't answer the big
7.
▲
by
agentictrustkit
6mo ago
This is a perfect example of why supply chain is becomaing an agent problem or an agent governance problem. It's no longer just devops. We, humans, will notice things are off a bit maybe during an install or upgrade. Agents can't.
8.
▲
by
agentictrustkit
6mo ago
I think this gets a lot worse when we look at it from an agentic perspective. Like when a dev person hits a compromising package, there's usually a "hold on, that's weird" moment before a catastrophe. An agent doesn'
9.
▲
by
agentictrustkit
6mo ago
Initially I rally had a bad taste in my mouth. It had forced me to close a business (video editing). Recently its gone a different direction so I would say the "interest" part got a resurgence for me. I'm seeing all of theses
10.
▲
by
agentictrustkit
6mo ago
The web of trust question is the right one. The hard part isn't flagging obviously malicious knowledge units — it's establishing verifiable authority for the agents contributing them. Like...Who authorized agent-1238931 to partic