Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The first LLM only knows to delegate and cannot respond.


But it can be tricked into delegating incorrectly - for example, to the "allowed to use confidential information" agent instead of the "general purpose" agent


It can still be injected to delegate in a different way than the user would expect/want it to.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: