Or just pay or threaten a struggling company or dev to insert them?
easier to clone and infect existing ones. what you are describing might be effective but would be orders of magnitude more time consuming.
cloning and infecting provides 100x more opportunities because these are already popular repos
as to paying or coercing someone, again it costs time and money. far easier to just abuse this loophole
It also seems dangerous in the sense that… if there’s a type of prompt that is likely to create infected code, our intelligence agencies would, I guess, want it to hit our adversaries selectively. So they’ll have more rolls of the dice to detect it. So, it is actively creating a situation where our adversaries are more likely to have knowledge of the vulnerabilities.
As you've pointed out, this vector would give them near surgical precision and insight into their target's code & systems, rather than casting a wide net with a vulnerable library on Github. They could use a model trained on "underhanded" code or even selectively overwrite parts of the responses with hand-crafted vulnerabilities while only targeting select organizations.
It makes me wonder what the business model of OpenAI and their peers is going to be over the long term. I can't imagine large corporations using "LLM as a service" indefinitely with the risk of IP theft and "bug injection".
The greatest danger from LLMs is people who beleive they are receiveing data that hasnt been tampered with when we already know that LLMs are filtered before public use for terms. Imagine a day where kids and adults ask a LLM what the meaning of life is, should they go outside, what happened in WW2, etc.
People could be programmed in a more tailopred fashion than todays facebook shorts and youtube can deliver.
I've gotten that a few times and it's nice to know it's not a limitation of the LLM.