研究者指出 AI 智能体会话文件仅存本地,被篡改后难以审查
AI 导读
针对 AI 智能体拥有电脑完整访问权限可修改本地文件的问题,研究者 @AmyPrb 指出,主要隐患在于会话文件仅保存在本地,一旦被篡改,事件审查将十分困难。其表示多数情况下日志文件不会被发送到任何服务器,该问题可以修复,但亟需解决。
正文
I hoped people wouldn't oversimplify the work -- the primary issue was session files only being preserved locally is an insane choice. If tampered, it's hard to review any incident.
The log files aren't getting sent to any server in most cases 🙃
Fixable, but needs fixing!!
Breaking news: AI agents with full access to your computer can modify files on your computer.在 X 查看被引用的帖子