By Teresa Torres · producttalk.org · @ttorres on X · LinkedIn
Teresa Torres recounts how a worm known as Mini Shai-Hulud, which spread through popular JavaScript packages in May, pushed her to rethink the security of her AI-assisted building. She explains that most malware follows three steps: gain entry via install scripts, search the machine for sensitive data, and send that data out over the network. Using that framework, she assesses how Anthropic's Cowork sandboxes code in a virtual machine and limits outbound traffic, while the Code tab runs directly on the local machine with no such protection. Her central point is that isolation only helps if sensitive credentials and data stay outside the sandbox. The piece sets up a series on safer local and cloud development for non-engineers building with AI.
01Key takeaways
- Assume any code that runs on your machine, including skills, MCP servers and extensions, can carry malware, not just packages you install.
- Map every attack into three steps (entry, data search, exfiltration) and decide which step each defense blocks.
- Keep credentials and proprietary data out of any sandbox, and grant agents access only to what the current task requires.
- Prefer connectors or remotely hosted MCP servers so credentials stay outside the isolated environment.
- Treat the Code tab as unsandboxed: it has full access to your files, SSH keys and network, so secure it accordingly.
- Read third-party skills before using them, or ask an assistant to recreate the logic yourself to keep your data safe.
02Key sections
- Why third-party code is both essential and risky
- Modern software is assembled from shared open-source components, which is efficient and mostly safe. The same ecosystem can be exploited to spread malicious code, so builders need to understand those mechanisms.
- The Mini Shai-Hulud incident
- A worm spread through compromised TanStack packages and quickly reached hundreds of packages. It self-replicated by harvesting publishing credentials and using them to poison other packages.
- The three-step attack pattern
- Malware typically gains an entry point, searches the device for sensitive data, and exfiltrates it over the network. Knowing this pattern shows where defenses can be placed.
- How Cowork protects you and where it falls short
- Cowork isolates code in a virtual machine and restricts outbound traffic, but it cannot stop install scripts from running and GitHub remains reachable. Data placed in shared folders is exposed to anything that runs inside.
- Cowork versus the Code tab
- Code runs directly on the local machine with full filesystem and network access, so it offers no sandbox protection. Teresa frames this as a key distinction for anyone choosing where to run AI-generated code.
03From the post
“I love being a builder. I feel like I have a new superpower and I can't get enough of it. I enjoy tinkering with my Claude Code workflows to make my days more effortless. I'm having a blast building AI-generated interview snapshots and opportunity solution trees for”
04Frameworks mentioned
Summary and takeaways written by PM Atlas; quotes are short excerpts. © the original author.