Today I started using AI in my CI CD for SkillSpector https://github.com/nvidia/skillspectorThis hasn't been easy. https://github.com/nvidia/skillspector 1. it's too slow. GitHub bills by the minute2. it's obscure. How would an LLM know that it's being deceived (prompt injection). LLMs are not trained to detect deception at scale3. SkillSpector uses multiple vulnerability patterns.64 vulnerability patterns across 16 categories:prompt injection, data exfiltration, privilege escalation, supply chain, excessive agency, output handling, system prompt leakage, memory poisoning, tool misuse, rogue agent, trigger abuse, dangerous code (AST), taint tracking, YARA signatures, MCP least privilege, and MCP tool poisoningWhile this is impressive on paper, attackers just need to add AppleScript or PowerShell. It will not detect a custom script, that adds a LaunchAgent if the code is obfusctaed.4. I added ClamAV to my Dagger pipeline (good will). https://github.com/norandom/Skills/blob/main/.dagger/...
Related
Hello Mastodon!I'm Jaison, a Salesforce Consultant passionate about building scalable CRM solutions.I share:• Salesforce...
Hello Mastodon!I'm Jaison, a Salesforce Consultant passionate about building scalable CRM solutions.I share:• Salesforce Admin tips• Apex & LWC• Agentforce• Data Cloud• Integration...
From dialogue to delivery. Across the Global AI Governance Dialogue, #AIforGood & #WSIS20, @UNESCO advanced human-centre...
From dialogue to delivery. Across the Global AI Governance Dialogue, #AIforGood & #WSIS20, @UNESCO advanced human-centred #AI through new partnerships, publications, capacity-build...
AI’s finally expensive enough to make Wall Street nervous, https://www.theverge.com/ai-artificial-intelligence/972119/ai...
AI’s finally expensive enough to make Wall Street nervous, https://www.theverge.com/ai-artificial-intelligence/972119/ai-stock-fall-google-capex.> It’s earnings season, and investo...