maxfurman 2 days ago

But it can be tricked into delegating incorrectly - for example, to the "allowed to use confidential information" agent instead of the "general purpose" agent

rafabulsing 2 days ago

It can still be injected to delegate in a different way than the user would expect/want it to.