For Claude Code you can maybe save context by putting the commit message formatting in a skill, so only the front matter goes into context at startup and the details only when the skill fires.
I’m not sure that’s quite the right framing. If Anthropic goes bust, Fable persists as an asset that can be run by someone who didn’t have to pay to develop it, probably profitably, and probably in a way that gets cheaper over time. The debt pony show is paying for the next model.
> AUR is just a collection of user-produced PKGBUILDs.
Is that much different from the entire pypi ecosystem, and npm, and dockerhub (people disable Selinux, --privileged turns off seccomp and apparmour, sandbox escape CVES exist)?
Not much different no, and people have equally bad practices around programming package managers as well.
The entire dev ecosystem has terrible security hygiene, largely because of the pressure to move fast and real security controls by their nature limit flexibility and can slow most processes down.
The main llm will refuse to scan for issues flagged or not, and the cheap model not do a good enough scan on its own.
For models designed/marketed for cybersecurity defensive uses, any predictable refusal mechanism is a vulnerability. It is like being able to cause a kernel panic or segmentation fault .
Even if the gate is fail-reject, an attacker can overwhelm HITL reviews with many false positives and use DoS vectors here.
Intriguing... "After months of misdiagnoses Dr Souhel Najjar, employs a test asking Susannah to draw a clock. Instead of the customary clock face, her condition led her to draw all the numbers 1 through 12 on the right side of the clock. This was the breakthrough moment; it was this clock drawing that enabled Dr Najjar to understand that the right side of Susannah’s brain was inflamed, further test revealed this inflammation was a result of anti-NMDA receptor encephalitis, initiating her path to recovery"