33 points atomburst 4 hours ago 19 comments
getatme32 4 hours ago | parent
embedding-shape 4 hours ago | parent
If this tool is returning even a single hit from this, you're probably using these agents wrong. You really want to run these in a way so they cannot touch your system drive/general filesystem that you use to do real work on. Even SOTA models at the end of their context limit behave REALLY illogical and does mistakes frequently. Don't run them straight on your machine unless you have backups and confirmed your backups work.
msdz 4 hours ago | parent
cortesoft 3 hours ago | parent
You start really locked down, and you read and approve every request for access. You do this for a while, but never see a result you deny, so you stop reading as closely. You keep hitting that approve button. You start paying even less attention to it. You start feeling silly, like you are simply slowing the process down. You get frustrated, because you keep coming back to your session and realizing your agent has been stuck waiting for approval for a long time, and the task that would have been done by now hasn’t even started.
Now you are running even more simultaneous sessions, which means more and more of your agents are stuck waiting for your approval. You feel even sillier, because you are taking even less time now to review and approve requests, but your review step is causing more and more slowdowns because you have more sessions going so you take longer between approvals. You feel like you are spending most of your time cycling through sessions hitting approve. You still have not come across a request that was dangerous or would have caused an issue, so you feel more and more like you are wasting your time.
So you slowly start to give your agents more access with fewer review steps.
Maybe this results in a catastrophic failure at some point, or maybe it doesn’t.
embedding-shape 3 hours ago | parent
bigstrat2003 3 hours ago | parent
Muromec 4 hours ago | parent
Haven't seen any close calls so far. The thing just behaves. Nothing of the horror stories of eremerefing the whole home directory or a database. Am I just lucky?
embedding-shape 4 hours ago | parent
Muromec 4 hours ago | parent
Right, that's kinda the same failure mode as delete from table something and hitting enter before you write the condition or writing the wrong one. If you reach the point where you opened the terminal to do it this way you already lost.
embedding-shape 3 hours ago | parent
I'm not sure what this means, the model and agent harness is the ones "opening the terminal and running this" (via a exec_shell tool or whatever), they do mistakes like this sometimes. Sometimes the scope is bigger, sometimes less, but anything below SOTA + higher reasoning efforts seems to fall into these mistakes sometimes.
Muromec 2 hours ago | parent
So do I, which is why I don't open the terminal to production database.
>anything below SOTA + higher reasoning efforts seems to fall into these mistakes sometimes.
We figured out how to deal with the human version of this mistake -- add a robust layer with build-in checks between the sloppy meatsack and production data and also make it annoying to access, so it does not become a habit and also requires high reasoning effort.
In my developer environment I can afford this mistake and can afford to delete everything I can touch. For some pieces the recovery will require more effort, but ultimately I can also have my laptop stolen on the way from the office.
On production however it will be a stack of forms to fill, a script with the dry-run and a four-eye rule to approve running it. We will also be able to recover production from the backup as we should. Or at least the company collectively believes so.
lukan 3 hours ago | parent
The trick is not go to that limit, but stay under 50% or even better 25% of context length. But backups are a smart thing anyway.
mdspan 2 hours ago | parent
dpflan 4 hours ago | parent
Muromec 4 hours ago | parent
ramen0w0 3 hours ago | parent
Betelbuddy 1 hour ago | parent