Yes. Don’t get me wrong: I use and enjoy these LLMs. But even now, well into 2026, I’m still using them via the now “old-fashioned” chat box in a web browser. Based on all that we’ve learned about this technology, there’s just no way I’m giving it control over any part of my machine. Is it a helpful search engine? Does it save me typing and write some nice code snippets when I need it to? Absolutely it does, and I greatly appreciate the technology. But I’m just not ready to create agents and let them run. I just think that’s still way too risky, and I fear a major, major catastrophe is coming because of how so many people recklessly trust these agents. I certainly hope I’m wrong.
last week i finally bit the bullet and did the vm thing and my harness exclusively lives in there now, no more env files for local dev keychain access only which is requiring a lot of input from me but oh well. i'm 100% web browser chat on my host system. i cannot afford to have my world compromised and i stalled on setting that up for way too long. all of these major services are inevitably going to get compromised they're just adding too many surfaces constantly it's insane.
i also ejected node/npm the fuck out of my world after the recent shai halud. In this "AI is assisting in finding vulnerabilities" era i'm just like done with the exposure. keeping vendored copies of any libs i need and mostly just use go now and making stuff that is effectively distroless for deployment and my build chain is pretty much just compiling my go, and even with go im carefully looking at packages theres so many packages appearing out of thin air now all vibe coded no reputation.
Me too, it is a crystal clear boundary between me and the LLM.
They might have access to my most precious code, but at least they don't have access to my browsing history.