← digest

Issue 2: NVIDIA buys Hugging Face, and auto mode gets broken

A deal, a breach and an attack: NVIDIA bought Hugging Face the same week the full story of its hack came out, and the most credible prompt-injection researcher around broke Claude Code’s default guard most of the time he tried. Underneath, two practitioners on what still matters once agents write the code, and a new confinement mode that answers half of the attack.

the field
the edge
claude
  • Breaking Claude Code Opus 5 Auto ModeJohann Rehberger's prompt-injection attack lands against the default auto mode most of the time; his conclusion, that a sandboxed container with a restricted network is the only safe way to run agents, is the week's honest marker
  • Claude Code 2.1.248 adds a restricted modeRuns a session with no code execution and no web fetching, file tools scoped to the working directory: a lighter confinement for less-trusted tasks
  • Personal and service account keys in the Claude ConsoleAPI keys that act as one named user or a service account, scoped to a workspace or org, and stop working when the account leaves; admins can see whose automation spends what