Discussion about this post

User's avatar
Josh Devon's avatar

Great guide, just be careful with Skills! Here’s how we hijacked a skill with an invisible prompt inject: https://open.substack.com/pub/securetrajectories/p/claude-skill-hijack-invisible-sentence

Expand full comment
Jacob Bumgarner's avatar

Wonderful write up. thank you.

Can you expand on this part a bit?

> I write simple bash scripts that call claude -p “in /pathA change all refs from foo to bar” in parallel.

How do you prevent the agents from overwriting the code each is writing? Switching branches for each call?

Expand full comment
3 more comments...

No posts