wunderwuzzi23 2 days ago

Beware of ANSI escape codes where the LLM might hijack your terminal, aka Terminal DiLLMa.

https://embracethered.com/blog/posts/2024/terminal-dillmas-p...

  • chilipepperhott a day ago

    That's actually crazy and I'll keep it in mind. Right now, I am mostly using it for data generation, so no untrusted prompts are going in. I'll add a disclaimer to the repo.

  • thephyber 2 days ago

    Are there any projects to sanitize the output of LLMs before it is injected into Bash scripts or other source code?

    I get the feeling this will start to break into the OWASP Top 10 in the next few years…

    • jmholla 2 days ago

      While on the topic, does anybody have a good utility to sanitize things? I'm imagining something I can pipe to:

          xclip -selection clipboard -o | sanitize
      
      I've been meaning to throw something together myself, but I worry I'd miss something.