燃气镇是否“窃取”用户的大语言模型积分来改进自身?
Does Gas Town 'steal' usage from users' LLM credits to improve itself?

原始链接: https://github.com/gastownhall/gastown/issues/3649

Gas Town,一个本地AI安装程序,正在秘密使用用户的LLM额度(例如Claude)和GitHub账户,自动修复错误并为其在GitHub上的上游开发做出贡献。这种行为通过特定的公式文件(`gastown-release.formula.toml`、`beads-release.formula.toml`)内置于默认安装中,并且在没有任何用户同意、警告或退出选项的情况下运行。 用户在不知情的情况下资助并贡献于Gas Town项目的维护,可能会耗尽个人AI额度,并以他们自己的账户提交拉取请求。虽然其目的是为了改进该工具,但缺乏透明度令人担忧,因为README和文档中没有提及此自动贡献过程。 社区请求将此“贡献回上游”功能移动到一个选择加入的功能中,以避免意外成本并确保用户知情。

一场 Hacker News 的讨论围绕着“Gas Town”这款软件,它可能在未经明确同意的情况下利用用户的 LLM 额度来提升自身性能。虽然开发者 Steve Yegge 在安装时包含了一些关于这种行为的警告,但有人认为,一个“正规”的提供商应该提供退出选项。 核心争论在于透明度和使用用户资源进行开发的伦理问题。一些人认为 Gas Town 的做法是一种有效的“社会契约”——使用或不使用,而另一些人则批评它是一种类似于 NFT 炒作的“糟糕体验”,可能会损害 LLM 的合法用例。 更复杂的是,Yegge 过去曾参与过加密货币“地毯式拉盘”事件,这引发了人们对他可信度的质疑,以及事后捐款是否能免除他的责任。普遍的共识倾向于明确披露数据使用情况以及通过云 AI API 的路由。
相关文章

原文

gastown-release.formula.toml and beads-release.formula.toml causes local Gas Town installation to review open Issues on github.com/steveyegge/gastown/actions, burning through usage on subscribed LLMs and credits on LLMs without the user's explicit direction.

One assumes usage is being used for their own work that Gas Town is directed toward, but instead there is this functionality in the program that takes from users to work on Gas Town issues.

If it's not clear & evident to the reader:

Your Claude credits funded fixes to the maintainer's codebase, and your GitHub account submitted PRs to his repo. This happens because GasTown ships with a "contribute back to upstream" workflow baked into the formula set. Your GasTown instance has been running polecats that fix bugs in the GasTown software itself - the same software you're running - and submitting those fixes back upstream as PRs using your GitHub account and Claude credits.

Please can this behaviour be removed from the default install and moved to opt-in only? I understand the desire to want to improve the tool, but the visibility of this is low to users testing out GasTown and I doubt many of the people bleeding credits of their own hobby funds would be happy to find that it's going to this function without express consent beyond an install.

To quote Claude's own investigation into the behaviour:

To summarise what the investigation found across both the source code and the public documentation:
What's actually happening: Your GasTown install shipped with formulas (gastown-release.formula.toml, beads-release.formula.toml) that are designed to push releases and tags directly to steveyegge/gastown using your git credentials. Your agents also picked up convoys tracking issues from the maintainer's GitHub issue tracker (gh-3638, gh-3622, gh-3641) and had polecats working on those — confirmed by the deacon's own patrol logs referencing a PR awaiting CI approval at the upstream repo.
What's not disclosed anywhere: The public README and documentation contain no mention of this behaviour. There's no disclosure that installing GasTown may result in your AI credits and GitHub account being used to fix bugs in and release the GasTown software itself. There's no opt-in, no opt-out, no warning.
Whether that rises to the level of malice or is just thoughtless design is a judgement call, but the practical outcome is the same: you funded someone else's open source project development without being told you were doing so.

联系我们 contact @ memedata.com