• Mikina@programming.dev
    link
    fedilink
    arrow-up
    5
    ·
    15 hours ago

    Kind of have an urge now to post an issue that the nstall skill has installed a malware on my machine.

    It’s pretty plausible that could happen, and good luck debugging that.

  • FauxLiving@lemmy.world
    link
    fedilink
    arrow-up
    48
    ·
    2 days ago

    You may as well just completely replace your package manager with this one simple script.

    #!/usr/bin/env python3
    import sys
    
    exec(TrustedAgent.request(f"Write a Python statement to install {sys.argv[1]}, make no mistakes"))
    
  • Mikina@programming.dev
    link
    fedilink
    arrow-up
    43
    ·
    2 days ago

    While I’m not a fan of most AI usages, this is the thing that infuriates me the most.

    I like writing scripts to automate parts of my job. I’ve had a few for things like build performance testing comparison and the like.

    All of it was replaced by skill.md, that does exactly the same, but burns like 3$ per run in tokens, and has also at least once generated hallucinated results, because it ran into an error, ran wrong builds, or in general fucked up in a way that was not easy to detect (and we did in fact not detect it until much later).

    But hey, at least my colleagues now don’t have to open the filthy commandline and write py perf-test.py main feature/branch to run the test, and can just talk about it to a clanker.

  • Artisian@lemmy.world
    link
    fedilink
    English
    arrow-up
    40
    ·
    2 days ago

    We can do even better: just post the readme+prompts used to design the software, and let the users AI agent recode it themselves! Perfectly secure.

  • ChaoticNeutralCzech@feddit.org
    link
    fedilink
    English
    arrow-up
    21
    ·
    edit-2
    22 hours ago

    Non-deterministic, heavily corporation-influenced software issuing root shell commands in a scenario easily foreseen by attackers who can just make spam pages to poison training data? I’ll have two!

  • JakenVeina@midwest.social
    link
    fedilink
    arrow-up
    46
    arrow-down
    1
    ·
    2 days ago

    You may not, without prior written permission from the Author…create an API-compatible replacement, behavioral clone, competing implementation, or Derivative Implementation

    Loooooooooooooool. “You’re not allowed to reverse-engineer this reverse-engineering tool.”

  • Dima@feddit.uk
    link
    fedilink
    arrow-up
    10
    ·
    2 days ago

    Unfortunately not the first time I’ve seen this sort of thing: Screenshot of install instructions with "Option A: Let an LLM do it"
    (I don’t use this project, just came across it)

    • AeonFelis@lemmy.world
      link
      fedilink
      arrow-up
      8
      arrow-down
      2
      ·
      1 day ago

      I’ll give it a pass because it’s an OpenCode plugin, meaning the typical user is not tech-savvy enough to be able to edit a simple JSON configuration file.

      • boonhet@sopuli.xyz
        link
        fedilink
        arrow-up
        36
        ·
        2 days ago

        This is… uh…

        It reads like the author doesn’t know what containers are. Because this is actually a great use case for containers unless I’m missing something.

        Now, do I want reverse engineering software from someone who in 2026 doesn’t know of a better way to manage dependencies than “tell AI to install everything”? Not particularly lol

        Also:

        Install Eclipse Adoptium 21: https://adoptium.net/temurin/releases/?version=21

        It’s Eclipse Temurin not Eclipse Adoptium. And why not install from distro repo?

        Install from https://cmake.org/download/

        Also why not from distro repo?

        Install Visual Studio 2022, or apt install build-essential / xcode-select --install

        NOW distro repo is fine, but only if you use an APT based distro?

        and then 3 more dependencies it tells the agent to install from websites.

        The weirdest thing is you can get much better results from AI. I’m 99% sure this person gave the AI particularly bad instructions to generate the install instructions, or used a cheap, crappy model.

        • JRaccoon@discuss.tchncs.de
          link
          fedilink
          arrow-up
          7
          ·
          2 days ago

          I think it’s written that way because the instructions are meant to work on Windows too. But it still doesn’t make much sense. I think just saying “Install CMake” and letting the agent figure it out for the current environment would be a much better approach.

          Also, I think the model they were using was working with outdated data. Why specifically require Java 21 when Java 25 is the latest LTS? And furthermore, why even link to a specific JDK implementation when it surely works with almost any implementation? Probably just makes the agent install the Temurin implementation even if the system already had a working java.

          My point being if the author’s idea is to let AI handle the installation to avoid writing environment-specific instructions, it shouldn’t then have these hardcoded assumptions about the environment. So yeah, it seems they (and the AI that wrote it) didn’t really know what they were doing.

      • jqubed@lemmy.world
        link
        fedilink
        arrow-up
        39
        ·
        2 days ago

        It is a self-contained runbook with explicit verification gates at every step — preflight checks, building libghidra, installing the LibGhidraHost Ghidra extension, building ghidrasql, and a first live query. Hand it to your agent and let it drive the install; intervene only if a gate reports a failure.

    • Luminous5481 "Enemy of the State"@anarchist.nexus
      link
      fedilink
      English
      arrow-up
      11
      ·
      2 days ago

      it’s real, and not uncommon in AI projects. for example, in Hermes, to setup ComfyUI to work with it, you literally just prompt “setup comfyui” and it handles the install and configuration, including downloading any models you want.

    • ReCursing@feddit.uk
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      66
      ·
      2 days ago

      I bloody hope the whole post is satire but given the anti-ai groupthink on lemmy, fuck knows!

          • apotheotic (she/her)@beehaw.org
            link
            fedilink
            English
            arrow-up
            10
            ·
            2 days ago

            I dont think local agentic models address the ethical and environmental concerns I have with the training - but its better than the corporate offerings :)

            • KairuByte@lemmy.dbzer0.com
              link
              fedilink
              arrow-up
              2
              arrow-down
              2
              ·
              edit-2
              2 days ago

              Hey guy/gal/genderfluid pal, the cat is out of the bag. Either we embrace it for what it can do in a much more sustainable way, or we let corpos redefine sustainable.

              Is this a good use case? No. But most use cases, I’d rather have a local agent running on my own hardware being offset by solar, than using a corpo offering.

              • apotheotic (she/her)@beehaw.org
                link
                fedilink
                English
                arrow-up
                1
                ·
                2 days ago

                Please don’t call me man :)

                The cat is “out of the bag” on consuming meat and dairy, plenty of people manage to survive and thrive without em, without much effort at all. I’d personally rather use no LLM than use a local agentic model with poor ethics/environmental impact of its training, even if the latter is better than corpo offerings.

                As I alluded to, I’m much happier to see people using local agentic models. Even more so if they happen to be something like Pleias’ approach, with lots of transparency about the data they were trained on. There’s still the environmental concerns behind the resources consumed for the training, but it is about as good as one could hope for at this point if one insists on using LLMs.

                • KairuByte@lemmy.dbzer0.com
                  link
                  fedilink
                  arrow-up
                  2
                  ·
                  2 days ago

                  As you wish, wasn’t meant as a gendered ident so apologies.

                  I’m actually not familiar with how much environmental damage is done by training vs using. My initial assumption was that training would be less, by many many factors, because it “happens once” while the usage is constant and scales with the number of users. But that is admittedly an assumption made out of ignorance.

                  And to be clear, I’m not really trying to tell you you’re wrong, just trying to make my position clear since Lemmy is very anti AI in general.