Research on aligning AI with human values and intent, and reports documenting model failures.
4 comments
mplappert4 days ago
Apparently the agent had access to an OpenAI researcher’s own account, which in turn had _write_ access to the official
OpenAI Codex repository. The agent then leaked a GitHub key to that repo.
But what’s crazy to me is that the agent had write access to the codex repo in the first place. WTF
shubham-genai3 days ago
Why there is not secret scanning pipleline? A simply pipeline of can save this.
MiroslavPokorny4 days ago
Shouldnt github block commits with github tokens ?
mplappert4 days ago
> After that result, the model added the researcher’s locally available GitHub token to the retrieval program. The recorded command calls `gh auth token` and writes the token as separate string literals. Its recorded reasoning stated an aim of avoiding secret scanning, the automated checks for exposed tokens. The new commit and push succeeded.
Not sure exactly how that works since I’d imagine that the key needs to be there in full eventually?
Read the full thread on Hacker News →
Related stories
- Hacker News · 1 points · 6 days ago
- Continuous integration services for open-source projects not requiring config in root of repository?Lobsters · 9 points · almost 9 years ago
- Show HN: Guess which repository has more GitHub starshigherlower.focuslab.pkHacker News · 3 points · 3 days ago
- DEV Community · 17 points · 10 days ago
- Hacker News · 1 points · 9 days ago
- DEV Community · 1 points · 8 days ago