> but giving a 2B model full JS execution privileges on a live page is a bit sketchy from a security standpoint.
Every webpage I've ever visited has full JS execution privileges and I trust half of them less than an LLM
Every webpage I've ever visited has full JS execution privileges and I trust half of them less than an LLM
If you think about it, everything we've done to make malicious webpages unable to fiddle around with your state on other sites using XHRs, are exactly and already the proper set of constraints we'd want to prevent models working with webpages from doing the same thing.