ES version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
60% Positive
Analyzed from 616 words in the discussion.
Trending Topics
#should#repo#read#didn#openai#why#codex#code#using#cleaner

Discussion (16 Comments)Read Original on HackerNews
Operator error exists with or without AI. Installing any dev tool that could exfiltrate your information means you are responsible for securing your environment.
Use a devcontainer. You can find starting examples on the official claude code and codex github repos. Configuring a firewall script to block egress. That being said, you will likely allowlist openAI domains so I'm not certain if the sites feature will be blocked. Worth testing.
"The part I have to be Fair about" "Why it did this", "Why this should bother you", "honest framing", ...
The things you are doing differently are not legitimate guardrails either. An AI article warrants AI-generated criticism, so I'm not going to say more.
I don't mean this to downplay your experience, and I agree it should be opt-in by default, but any software engineer using these tools should understand completely that in order to 'read' your repo it needs to copy it all to the provider's servers. Using anything short of a local model has ALWAYS been a complete leak.
Same principle applies to the grok build fiasco a few weeks ago.
I get what you’re saying about how you’re inherently trusting them by using their LLMs, but it’s different from pushing up the entire repo and git history to some server I didn’t ask for. The skill should ask if the user wants to upload to openAI “sites” or whatever the feature is called.
Maybe they invent some file format proprietary for their projects.
Most likely they run more and more in the cloud such that it's harder to switch away to cheaper models.