Like if someone purposefully runs at a brick wall, it's just fine to go <nelson>HA-HA</nelson> at them. Did they expect a different result than pain?
At best someone extracts 0-59 minutes of a session key for my aws credentials for one development account, boring, whatever source code is currently on the machine, also boring,
There's more risk that vetting someone on Upwork goes wrong and they burn me than Claude does.
Am I blind to the actual risk here? how many of you execute unverified code from libraries without a sandbox?
I sell bespoke SaaS solutions to mid sized businesses. Really really boring stuff. My moat isn't my secret super duper fast software or secret client list, it's that I can integrate and iterate faster than others can in the same space.
Part of that value comes from letting Claude do his thing.
I'm not running it on my personal computer or anything with cookies, private keys, or anything like that.
It's not like I'm running it where it could cause mayhem. If I ever run it on the PCI-DSS infra, please feel free to terminate my existence because I've lost the plot.
I have a script which clones a VM from a base one and setups the agent and the code base inside.
I also mount read-only a few host directories with data.
I still have exfiltration/prompt injection risks, I'm looking at adding URL allow lists but it's not trivial - basically you need a HTTP proxy, since firewalls work on IPs, not URLs.