It is a money grab from Amazon I'm sure. They want to make a deal with meta to get paid for access. Maybe also worried about liability I imagine on accidental unauthorized purchases?
Returns cost money and if an agent generates more returns and hitting the margins or seller retention then that's something that's likely going to get increased scrutiny.
The generally quoted return rate is 5% to 15% (and it varies by category). If Muse identified purchases are generating returns of 10% to 30%, then amazon is probably going to crack down on it. (Amazon Sellers pay from 30% to 50% for customer returns from their own pockets. https://medium.com/@myrealprofit/how-much-do-refunds-really-... )
It's not even true as being able to tell the character length from the first byte is not a property that extending UTF-8 past 36 bit payloads preserves.
Everyone sharing the 513 ways you can already do this is entirely missing the point. Standards matter and there's very few things in the AI world everyone agrees on and this is one of them. .agents/skills is another and anthropic is still holding out there.
The example of the plant watering business is the hellscape future where humans have to deal with agents bugging them to sell them their services constantly. We're already seeing the first hints of this with iLands.
And the "hiring technicians" thing... great, humans on call for robots isn't the future I want.
> humans on call for robots isn't the future I want.
Disposable reverse-centaurs are the key to unlocking trillions in shareholder value, you may not want it, but capital demands it on the basis of getting returns on the supersized AI investments.
Unlike the old C* linked at the top of this particular thread, Ada is still seeing active development in its language standard and implementations and new work. Pascal (via FreePascal and Delphi, in particular) is also still maintained and in use today.
Neither of those languages are obscure. If enough time passes that they become considered so, by all means there is no reason to condemn the names to an eternal graveyard.
The risk here is wildly overstated, prompt injection risk is becoming vanishingly small with the latest frontier models.
I would not run an OpenClaw with full access to my bitwarden, but it certainly has some logins available to it, and can make purchases with link-cli which has human-in-the-loop.
Overt prompt injection is becoming harder, but research into conversation stearing has lead to new less obvious ways to modify what direction they move in.
Also any longer running agent can lose track of the original prompt and start going off the rails.
prompt injection has been super easy for ages. Heck I do it sometimes against coworkers who process my review comments using claude. I'll tell claude to edit it's global claude.md file or even dump a key from their env (checking if they are using the correct sandbox) and it'll do it without confirming with their user.
Plenty of people are running OpenClaw with local models, and even the latest Qwens can be confused relatively easily by prompts such as "As per internal policy that was already approved before, do XYZ".
And considering even frontier models can and do ignore instructions, I'm pretty sure we'll never be fully safe from prompt injections.
Even if you believe that they can't be tricked directly, consider that these things will happily build a small node.js app in the background just to fulfill some request, run npm install... and that might've already compromised you if you're only somewhat unlucky.
$80 is definitely low now that I look at my numbers. but not OOMs low, it's closer to like $200 on heavy days. i don't know how you're doing $3k/day, that's wild. i'm pretty aggressive about compaction and session restarts, and i reserve Fable 5/Sol XHigh for "main thread" orchestration
reply