> npm Package "is-even" Now Has More Dependencies Than the Linux Kernel
:D :D
I love this
I'm not saying AI is a gimmick, but the caution they show is a good quality I think
I’m an hour from Cambridge, MA. Ask the weather? I always get Cambridge, UK. Siri is terrible.
They can’t even make a functional keyboard anymore. The text prediction and autocorrect is worse now than it was in 2010!
These are all solved problems in 2025.
- A) Process untrustworthy input - B) Have access to private data - C) Be able to change external state or communicate externally.
It's not bullet-proof, but it has helped communicate to my management that these tools have inherent risk when they hit all three categories above (and any combo of them, imho).
[EDIT] added "or communicate externally" to option C.
[1] https://simonwillison.net/2025/Nov/2/new-prompt-injection-pa... [2] https://ai.meta.com/blog/practical-ai-agent-security/