Highlights include:
I see the commits say they were co-authored by Claude, but from having read the code, I think you haven’t given Claude enough credit.
I wish I was their credit card, because then I might finally be in a happy relationship with someone who loves to use me this hard.


If opening inspect element and looking at a website’s served HTML is hacking…
Three-in-one computer crime: prompt injection which instructs their agent to open inspect element in a browser and then download all of the scholarly works off of JSTOR.
Yeah, some of the ‘hacking’ allegation are amazing, so maybe we will one day see ‘my agent was asked to drop database by a page I was scraping without permission’ lawsuits.
Yeah… If adding +1 to the URL bar, and accessing another customer’s data, with zero access control is “hacking”; then you could argue that maliciously “laying a trap” for an A.I. agent is hacking.
I dunno, it’s a strange world we live in. Plain English language hacking. I never would have imagined just telling a computer to malfunction in a plaintext document would ever actually work.
Well, scamming was plain English hacking before the invention of electricity, so maybe we’re just back to the basics