Anyone who gives an LLM unfettered access to their ssh keys/agent socket deserves what they get IMO. I sandbox Claude with my own bubblewrap-based script which denies it access to anything I deem unnecessary.
There's many ways to shoot yourself into the foot, most things that run in your userspace can do evil things and it's not an LLM exclusive feature. Any npm package you install on your machine can put you in danger already if it executes some scripts.
Comments
Anyone who gives an LLM unfettered access to their ssh keys/agent socket deserves what they get IMO. I sandbox Claude with my own bubblewrap-based script which denies it access to anything I deem unnecessary.
There's many ways to shoot yourself into the foot, most things that run in your userspace can do evil things and it's not an LLM exclusive feature. Any npm package you install on your machine can put you in danger already if it executes some scripts.