PyTorch AI PR review can treat attacker filenames as system text
Untrusted paths from fork pull requests were fed into the model as trusted hook context, enabling prompt injection without model cooperation.
By tensorUntrusted paths from fork pull requests were fed into the model as trusted hook context, enabling prompt injection without model cooperation.
By tensorReid Kleckner proposes lower commit access, a smaller reviewer class, and mandatory code-owner approval on every pull request.
By rvalue