• Artisian@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    We can do even better: just post the readme+prompts used to design the software, and let the users AI agent recode it themselves! Perfectly secure.

  • Mikina@programming.dev
    link
    fedilink
    arrow-up
    0
    ·
    2 months ago

    While I’m not a fan of most AI usages, this is the thing that infuriates me the most.

    I like writing scripts to automate parts of my job. I’ve had a few for things like build performance testing comparison and the like.

    All of it was replaced by skill.md, that does exactly the same, but burns like 3$ per run in tokens, and has also at least once generated hallucinated results, because it ran into an error, ran wrong builds, or in general fucked up in a way that was not easy to detect (and we did in fact not detect it until much later).

    But hey, at least my colleagues now don’t have to open the filthy commandline and write py perf-test.py main feature/branch to run the test, and can just talk about it to a clanker.

  • Mikina@programming.dev
    link
    fedilink
    arrow-up
    0
    ·
    2 months ago

    This will be a goldmine for malware groups that are poisoning AIs that use web search to get them to use their malware-ridden version of software and libraries, and I’m here for it with popcorn at the ready.

    I kinda hope this will get more common, because the only people affected kind of deserve it, plus it’s a great way how to filter sloprojects at a glance.

    • I don’t think that poisoning really works. They have AIs judge the answers before they incorporate them into the new AI. They can tell the best topping for pizza isn’t actually mayonnaise and strawberries

  • NCSK@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    2 months ago

    Isn’t this actually kinda what AI is good for? I mean a simple task that just takes time and has step-by-step instructions, and you can just let it handle it and do it faster. Like its almost as good as writing a long script that just does it for the user?

    • Mikina@programming.dev
      link
      fedilink
      arrow-up
      0
      ·
      2 months ago

      As someone who had his relatively fine and deterministic scripts replaced by skill.md bullshit by coworkers – no. This is exactly the things AI is the worst fit for.

      We’ve already ran into it halucinating complete result data-set, because it ran into an error but the skill mentioned that it should give the results data to the user. So it just made it up, since it couldn’t get it by following the correct process.

      It has also ran wrong builds or input parameters, because it confused their order.

      I’ve also seen it skip a step.

      I’m pretty confident that the AI running this script will eventually, for someone, run into an issue with getting one of the dependencies, and go on a wild goose chase in trying to satisfy it, eventually running into one of the typosquatting malware repositories or clones. Not to mention that there are groups that are actively poisoning AIs that search the web to feed them their malware-ridden typosquatting libraries instead.

      If you suck so much you can’t write a simple script like this (or just can’t be bothered), you should at least just ask the AI to write it for you, so you have a deterministic set of steps that you are confident will always behave the same.

    • bamboo@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      The install process should be deterministic. When you run sudo make install it should do the same thing every time you run it. If this process fails, it’s because of a missing dependency or permission issue or something like that. The failure should never be because of a statistically probability during installation that causes the installer to go off and do something wildly different.

    • abbadon420@sh.itjust.works
      link
      fedilink
      arrow-up
      0
      ·
      2 months ago

      No. If you look at the instaal prompt, it is just a step by step instructionon how to check the environment, download the script, build the app, run the app, test if it is all good.

      That is the whole install prompt. There is literally no need to waste a million tokens on that when a simple bash script can do it for free.

      If you’re going to use AI for this, ask it to write you a bash script that does all these things. Maybe even a ps1 script to go with it.

    • Cabslock@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      2 months ago

      A script uses much less power/water I suppose… And, wouldn’t you have to pay tokens for an AI to do those things? Or are you expected to set up a local model or something for this?

      • JensSpahnpasta@feddit.org
        link
        fedilink
        arrow-up
        0
        ·
        2 months ago

        An agent installing that should not use that much power or water. The issue here is that you do not want an agent running on your system being able to install stuff from the internet

    • JRaccoon@discuss.tchncs.de
      link
      fedilink
      arrow-up
      0
      ·
      2 months ago

      Yeah, but I would never let an AI agent run commands on my machine without verifying each command. And at that point I would just rather copy and paste commands by hand, takes about the same time.

      If the installation for example required creating some complicated host specific config files, then sure, I could see how that kind of a “runbook” could maybe be useful. But that doesn’t seem to be the case here.

      • OwOarchist@pawb.social
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        Yeah, but I would never let an AI agent run commands on my machine without verifying each command.

        I would never let an AI agent run commands on my machine, period.

        Because that’s how you get “You’re absolutely right. I did make a mistake when I deleted your entire /home and /backups directories while executing that command. Great job noticing the error!”

        • Lauchmelder@feddit.org
          link
          fedilink
          arrow-up
          0
          ·
          2 months ago

          honestly if your backup folder is on the same machine as your home folder you deserve everything that comes your way

          • OwOarchist@pawb.social
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 months ago

            Regardless of where your backup folder is, your machine needs writable access to it in order to make new backups.

            And if an AI agent has root-level access on your machine (needs root to install things), then it will be able to access that backup folder and potentially be able to delete its contents.

    • atopi@piefed.blahaj.zone
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Arent computer programs already a set of instructions? Why add a really big program that inputs instructions in a different format and that is worse at following those instructions because that was not what it was mode for

  • Unleaded8163@fedia.io
    link
    fedilink
    arrow-up
    0
    ·
    2 months ago

    If you trust the site, curl | sh is no worse than any other install method. If you don’t trust the site, it’s also no worse.

      • FishFace@piefed.social
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        Do you mean curl | cat or do you really want to create a file called cat?

        Also piping to cat seems redundant but malicious hosts can detect whether the request is getting redirected, using some clever trick, so it’s not.

        Also, your chance of spotting something bad in a malicious script is probably quite small.

        • cenzorrll@piefed.ca
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          This is my opinion on curl | sh/bash type directions. If the maintainers don’t provide a hash so I can confirm that is what they intended, there ain’t much I can do unless someone slapped in a function named “totallyNotMalware” into the script. I’ve looked through scripts, seen what they do, but I’m not good enough to recognize anything funky.

        • Dumhuvud@programming.dev
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          Also piping to cat seems redundant but malicious hosts can detect whether the request is getting redirected, using some clever trick, so it’s not.

          Just so you know, servers cannot detect piping to any arbitrary process. The trick you’re talking about is detecting piping to an interpreter, for the lack of a better term. Piping sleep N to bash is observable behaviour, for example. Piping anything to cat is not.

          https://web.archive.org/web/20250622061208/https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/

        • xthexder@l.sw0.com
          link
          fedilink
          arrow-up
          0
          ·
          2 months ago

          Saving it to a file is actually a decent method, since you can be sure the script you’re reviewing is the same one you’re running.

          Personally I often will just manually run the install steps in order if the script is simple enough. Half the time it’s just a bunch of OS version checks followed by a tar -xf

        • Ghoelian@piefed.social
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          If you just run the file you just created, it doesn’t matter that they detected a redirect. I mean it would be a bit silly to download a script, check it, and then re-download it to pipe into bash.

    • not_IO@lemmy.blahaj.zoneOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      that’s why you install from repos managed by people you trust, it’s like an app store without all the evil

  • Evotech@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    2 months ago

    I regularly have ai agents install shit for me lol. I just point it at a repo and say «deploy this for me» (in sandboxed environments)

    But i question this approach very much.

    • NιƙƙιDιɱҽʂ@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      2 months ago

      I disagree with it but think it’s fine if that’s what you’re comfortable with for whatever you’re doing on your system, but for the repo maintainer to make that the de facto way to install your software is absolutely wild and speaks leagues of the quality of the software you’re about to install…

      • Evotech@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        2 months ago

        Yeah. That is bad.

        But, it does speak to the capabilities. I’m sure you could offload all sysadmin tasks to an LLM these days. Just have it ssh in and do whatever you wanna do.

        • pressanykeynow@lemmy.world
          link
          fedilink
          arrow-up
          0
          ·
          2 months ago

          And as a bonus once in a while it will delete your database and backups so won’t ever need to do any sysadmin tasks at all. Optimisation!

        • littleomid@feddit.org
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          I’m sure I could also allow a child to do the sysadmin tasks that I do, but that would be an extremely stupid thing to do. Our systems can’t break. AI breaks shit constantly.

  • JakenVeina@midwest.social
    link
    fedilink
    arrow-up
    0
    ·
    2 months ago

    You may not, without prior written permission from the Author…create an API-compatible replacement, behavioral clone, competing implementation, or Derivative Implementation

    Loooooooooooooool. “You’re not allowed to reverse-engineer this reverse-engineering tool.”

  • vane@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    2 months ago

    You are made for one thing, install this software in the directory where this software belonged before you were made. You can read and understand markdown. Please install everything from this markdown file. Make no mistakes. Thank you.

  • Mikina@programming.dev
    link
    fedilink
    arrow-up
    0
    ·
    2 months ago

    Kind of have an urge now to post an issue that the nstall skill has installed a malware on my machine.

    It’s pretty plausible that could happen, and good luck debugging that.