PyTorch AI PR review can treat attacker filenames as system text
Untrusted paths from fork pull requests were fed into the model as trusted hook context, enabling prompt injection without model cooperation.
By tensorUntrusted paths from fork pull requests were fed into the model as trusted hook context, enabling prompt injection without model cooperation.
By tensorCrafted links can auto-submit prompts that invoke enabled server tools, including shell execution when confirmation is waived.
By tensor