openmic.social is an uncensored community. You may encounter strong language, controversial opinions, and mature or NSFW material. You must be 18+ to browse. Illegal content is prohibited and removed on sight — please report it. By continuing, you accept that you may see content you personally disagree with.
Yeah I used to use dev containers. Containers aren’t generally a secure sandbox. They’re a great guardrail for preventing accidents, but not so much with a malicious prompt injection. (I might be overly paranoid about these things.)
For tool version management, I usually set up a Nix Flake for each project (which also works inside dev containers).
You’re right, they’re not watertight. But I’m not trying to defend against MPI, just hallucinations. Never looked into Nix flakes, I always just used OCIs.