LLM links of the morning
2026-01-19 16:28:00.879639+01 by Dan Lyke 0 comments
install.md: A Standard for LLM-Executable Installation. As Ben Tasker @ben@mastodon.bentasker.co.uk notes:
TL:DR They've re-invented curl-bash but piping into an LLM instead....
Reprompt: The Single-Click Microsoft Copilot Attack that Silently Steals Your Personal Data:
Although Copilot enforces safeguards to prevent direct data leaks, these protections apply only to the initial request. An attacker can bypass these guardrails by simply instructing Copilot to repeat each action twice.
Via.
Futurism: Researchers Just Found Something That Could Shake the AI Industry to Its Core
Now, a damning new study could put AI companies on the defensive. In it, Stanford and Yale researchers found compelling evidence that AI models are actually copying all that data, not learning from it. Specifically, four prominent LLMs OpenAIs GPT-4.1, Googles Gemini 2.5 Pro, xAIs Grok 3, and Anthropics Claude 3.7 Sonnet happily reproduced lengthy excerpts from popular and protected works, with a stunning degree of accuracy.
Agent Psychosis: Are we going insane asks a lot of the same questions I'm fumbling with, but seems to come up in a direction that I'm not totally sure is useful. Whatever the current economic and environmental overreach, token cost is gonna go down. I doubt there'll be any real consequence for the massive IP theft and copyright violation. I'm more interested in the social and cognitive aspects, which... it's good to know we're all struggling with trying to express this.
The Lobste.rs thread includes observations like thirdtruck's:
Everything we've seen about LLMs makes it look less like the next tech revolution and more like the next tobacco industry.
spc476's observation that
So eventually, the prompt becomes the source code.
and the response from thesnarky1
For the people who like their compilers to be non-deterministic and potentially to act like a historical figure that had a tendency towards genocide if they read too many references to Wagner in the prompt conversation, yes.
and a link to Cursor's latest "browser experiment" implied success without evidence
Finally (for this post), curl: BUG- BOUNTY.md: we stop the bug-bounty end of Jan 2026. nixCraft 🐧 @nixCraft@mastodon.social notes:
curl, which is one of the most popular CLI/API tools for network requests and data transfer on Linux/Unix, is to discontinue its HackerOne bug bounty program due to "too strong incentives to find and make up 'problems' in bad faith that cause overload and abuse".
The authors simply cannot keep up with LLM-generated fake security reports created to collect money using bots. So, it now shuts down at the end of January 2026. This is why we can't have good things