this post was submitted on 31 Jan 2026
459 points (97.3% liked)

Technology

80724 readers
3730 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] ToTheGraveMyLove@sh.itjust.works 150 points 6 days ago (28 children)

The skill instructs agents to fetch and follow instructions from Moltbook’s servers every four hours. As Willison observed: “Given that ‘fetch and follow instructions from the internet every four hours’ mechanism we better hope the owner of moltbook.com never rug pulls or has their site compromised!”

Yeah, no shit. This is a fucking honeypot. People give these AI agents access to their entire computers, so all the site owner has to do is update the instructions to tell the AI agents to start uploading whatever valuable information they want? People can't be this fucking stupid.

[–] princess@lemmy.blahaj.zone 45 points 6 days ago (12 children)

doesn't even have to be the site owner poisoning the tool instructions (though that's a fun-in-a-terrifying-way thought)

any money says they're vulnerable to prompt injection in the comments and posts of the site

[–] BradleyUffner@lemmy.world 36 points 6 days ago (1 children)

There is no way to prevent prompt injection as long as there is no distinction between the data channel and the command channel.

[–] KeenFlame@feddit.nu 1 points 5 days ago (1 children)

I don't understand what you mean. Why is there no way?

load more comments (10 replies)
load more comments (25 replies)