I would _never_ give an LLM access to any disk I own or control if it had anything more than read permissions
I would _never_ give an LLM access to any disk I own or control if it had anything more than read permissions
I'm a few degrees removed from an air gapped environment so obviously YMMV. Frankly I find the idea of an LLM writing files or being allowed to access databases or similar cases directly distasteful; I have to review the output anyway and I'll decide what goes to the relevant disk locations / gets run.
If you were being really paranoid then I guess they could write a script in the local directory that then runs and accesses other parts of the filesystem.
I've not seen any evidence an agent would just do that randomly (though I suppose they are nondeterministic). In principle maybe a malicious or unlucky prompt found somewhere in the permitted directory could trigger it?
[1]: https://github.com/google-gemini/gemini-cli/blob/main/docs/c...