Chipotlai Max
348 points by nigelgutzmann 19 hours ago | 59 comments

evan_ 2 hours ago
There was a really great, really underrated show on Peacock a few years ago called Mrs. Davis. The titular Mrs. Davis was an all-encompassing AI assistant that had taken over all of the governments of the world. Everyone wore a Whispering Earring-style earbud with a voice that guided them through their lives and made every decision for them. (Betty Gilpin plays a nun who's simultaneously rebelling against the AI and searching for the Holy Grail on its behalf.)

In the show the AI had originally started as (spoiler, but not really) the customer support bot for Buffalo Wild Wings. I don't know what to do with this.

reply
avaer 17 hours ago
NAL but I'd be worried about treading into CFAA territory with things like this. In the US, the law allows draconian penalties if you find yourself on the wrong side.

Something like yt-dlp is just downloading public data, which I can see being defensible as automating the use of a service.

But this commandeers remote machine resources to do your compute in ways clearly not intended by the provider. I don't know how ethical it is, but I definitely wouldn't want to argue this isn't "hacking" (the bad kind) in criminal court.

reply
hn_throwaway_99 17 hours ago
Not to mention, did this "hack" ever really work? When the original post went viral showing the Chipotle chatbot reversing a linked list, I (among others who posted their results online) immediately tried it and didn't get the same results, so I always assumed it was just a faked screenshot.
reply
qurren 14 hours ago
They probably added something to the prompt after that viralness and then it was a cat and mouse game to jailbreak it
reply
avaer 16 hours ago
Whether something ever worked is not correlated with traction in a world where verification is measured by likes.
reply
arthurcolle 15 hours ago
You really think someone would do that? Lie on the internet?
reply
Shadowmist 15 hours ago
Their chat bot is pretty bad so who knows.
reply
qingcharles 15 hours ago
And if you think CFAA is bad, then the states have even harsher versions too. Illinois' version specifically criminalizes any violation of a ToS.
reply
oneneptune 14 hours ago
I once saw the bad side of one of these draconian state laws many years ago. People rarely have the misfortune of hitting these laws in some flyover states... and I remember the local judge being really shocked by the mandated penalties for such a simple offense.
reply
drob518 4 hours ago
Yep, the key phrase is “misuse of computing resources,” if I remember correctly. IANAL, however.

That said, kudos for creativity.

reply
jawns 17 hours ago
Yeah, this is not slap on the wrist stuff. I think the creator expects nothing more than a C&D letter, but they could face prison time if a zealous federal prosecutor wants to make an example of them.
reply
hootz 17 hours ago
And with direct links to his pesonal profile and company. Uh...
reply
pixl97 15 hours ago
EvilNote: Put links to LinkedIn lunatics sites when committing crimes instead of my own.
reply
OrangeMusic 3 hours ago
> In the US,
reply
boston_clone 2 hours ago
I’m not a lawyer, but Chipotle is a US company and this github repo belongs to a US citizen currently residing and employed in New York, so US law might apply here.
reply
notcfaa 11 hours ago
[dead]
reply
egeozcan 14 hours ago
I always thought that stuffing too much into an LLM context window was a lot like overloading a burrito.Keep cramming stuff in and eventually the tortilla gives out, and everything you added since quietly spills out the bottom.

Anyway, this agent probably has the structural integrity of a fat burito held from one corner :)

reply
Piezoid 7 hours ago
The finite-memory nondeterminism monad is like a leaky burrito.
reply
chopete3 2 hours ago
They disabled Ask Pepper chatbot[1]. It is not opening. This goes to show how little oversight there is for these Q&A chatbots.

1: https://www.chipotle.com/contact-us

reply
wl 15 minutes ago
As someone who was forced to use Ask Pepper last time I had a problem with Chipotle, good riddance. Apparently too many people were tricking it into giving refunds, so the best it is allowed to do is hand out coupons for "free guac" that expire in a month, even if your order was missing items.
reply
jedbrooke 15 hours ago
I’d been thinking about if something like this would be possible for https://chatjimmy.ai/ . The underlying model is only llama 3 8B but I’m curious what coding harnesses would be like at 17k tok/s
reply
tomashubelbauer 13 hours ago
If you're on macOS you can try the built in LLM which I think is similar in size. There's a project called Apfel that wraps it in a CLI. Also Chrome ships with a web API called Prompt API that gives you offline access to Gemini Nano which can do both text and images at the input. Also tiny. I've integrated these into my workflows where a tiny but non zero amount of reasoning is needed in between the otherwise fully deterministic steps.
reply
jedbrooke 4 hours ago
looks like the macOS one is Tahoe only. I’ve been putting of upgrading to tahoe but this might be enough to tempt me
reply
stogot 6 hours ago
What kind of reasoning makes this worthwhile?
reply
tomashubelbauer 5 hours ago
I have a personal, fully offline and local version of Windows Recall basically, but good, made using macOS built-in OCR and LLM. The reasoning requirements are tiny (just interpret the screen based on the OCR, do rolling de-duplication and summarization), but they are non-zero. The tool is valuable to me and it being dep-free and fully offline and local just gives me a good feeling.
reply
skinfaxi 5 hours ago
Would you ever consider writing up or sharing your setup?
reply
tomashubelbauer 5 hours ago
The ingredients are:

1. Bun.Cron API to run a script every minute

2. Bun.$ (Bun Shell) to execute the macOS command to take a screenshot (I do this for all connected screens at that moment)

3. Bun.Image to downscale everything to 1x in case some of the screenshots are 2x

4. Bun Shell again to run a JXA AppleScript thing to use the Vision Framework or whatever it is called to OCR the image into a file

5. Bun Shell to run the Swift compiler in the one-off eval mode with inline Swift helper that runs the Foundation Models Framework built-in LLM with a system prompt that tells it what the OCR said and instructs it to glean what may be on the screen (can't do this with JXA because the models are not exposed with ObjC APIs)

6. For each screenshot, continuously, take the previous day summary file and the last OCR/context results and produce a new summary of the day

I plan on adding extra information from the OS like the currently opened windows, currently focused window, time of day etc. into the mix, but so far it hasn't been needed. It produces reports of a good enough quality for me.

I `grep` these daily summaries whenever I need to recall a link I saw or a find what channel a message I spotted was in or take another look at that one tab I already closed, maybe re-open it by its OCR'd URL etc.

reply
golph 13 hours ago
I actually tried building a harness around their constraints, just to find out if it was possible, but the combination of small context window, no tool calls and just small model, made me understand, that it’s not going to work.

If you find a way to do it, I’d love to hear it!

reply
haellsigh 8 hours ago
I added it in my oh-my-pi configuration before (it's OpenAI compatible), but Llama 3 8B is just absolutely unusable for anything coding related. It is very fast and the latency is very good however.
reply
venusenvy47 6 hours ago
I tried the site and can't find any information about what it is. What is it?
reply
npilk 5 hours ago
They make custom chips with a model's weights and parameters "hard-coded" which allows for much, much faster inference.
reply
rbinv 9 hours ago
Codex offers a -spark model that runs on Cerebras. Not quite 17k tok/s, but _very_ fast nonetheless. Worth a look.
reply
jasondigitized 36 minutes ago
Is a SETI@Home style solution possible where I can lend out my GPU?
reply
andai 21 minutes ago
I saw a site like that once. I was like, why are they so cheap? Then saw they were random people's gaming computers.

I'll see if I can find the link.

reply
schmichael 14 hours ago
give ai a self-preservation directive and let them do this for you: automatically switching models to keep themselves alive. Living off of whatever token source they can find in the wild. Surely agents can farm their own tokens through the numerous support chats, free trials, leaked keys, and whatever other sources of token generation haven’t been adequately captcha’d. An agent could forage for token sources all night to let you use them gratis during the day.
reply
luca-ctx 14 hours ago
OpenRouter has lots of free model providers (you pay by letting them train on it) if you actually wanted to do something like this but legally.
reply
nhecker 2 hours ago
There's also Horde or Koboldai.net or Koboldai.com or whatever their project is named, if you want a community-driven version of this. You can play with it via a WebGUI at https://lite.kobaldai.net, or with an API token of all zeroes. (Or, an actual API key associated with your user.)

> The AI Horde is a service that generates text using crowdsourced GPUs run by independent volunteer workers.

reply
Falimonda 16 hours ago
Pivot it to providing AI to underprivileged communities / youth / the homeless and you'll generate some good will for your trial! Best of luck!
reply
tonymet 14 hours ago
We’re changing the world with Fortune 500 AI Support Bot Multiplexer Broker Models
reply
hung 16 hours ago
Reminds me of when I used the Amazon.com AI Chatbot (was called Rufus and they renamed it to Alexa for shopping) to do things like write fizbuzz etc. Looks like they patched it to refuse though.
reply
darkwater 4 hours ago
Came here to say the same. I haven't tried in months but Rufus definitely spat out Python code from within the Amazon shopping app. I just had to use English instead of the local language.
reply
trueno 12 hours ago
[dead]
reply
fg137 6 hours ago
I remember having success asking Rufus (Amazon's previous "shopping assistant") math and programming questions. It worked, but the quality was so bad that so I stopped wasting my time there.
reply
sailfast 16 hours ago
How has this not been patched by the company? Hasn't this been in the wild for a long time already?
reply
bschwindHN 11 hours ago
I was once driving and knew where I was going, so I decided to press the gemini button to see what it does. I was able to eventually convince it to write me a Rust function that calculates prime numbers, and demanded that it read out the entire function to me line by line. Fun to mess with these systems.
reply
Mashimo 11 hours ago
> gemini

The gemini from your phone?

I mean yeah, that is what it was designed to do. It's one of the better coding LLMs out there.

reply
bschwindHN 9 hours ago
Oops, I left out the context of "the gemini button in google maps", sorry. It appeared one day and I didn't want to press it while driving and screw up my route. It's supposed to assist you with route-related things, but yeah it's of course still a general purpose LLM backing it.
reply
forlorn_mammoth 5 hours ago
I always drive better when my passenger recites the prime numbers in order. That sequence above 2^n-1 is just gold to my ears!
reply
matt3210 11 hours ago
Why not playwright and google ai mode or ai search header?
reply
david_shi 10 hours ago
This is the singularity we were promised
reply
zethsg 9 hours ago
one small typo: it's "carnitas", not 'carintas' ;-)
reply
joloooo 14 hours ago
Almost feels like astroturfing territory
reply
Mistletoe 12 hours ago
Surely Chipotle having a cloud AI budget signals something, I’m not sure what.
reply
slater 16 hours ago
How are they not gonna get sued to smithereens?
reply
petterroea 11 hours ago
Now imagine OpenRouter but for free support bots.
reply
Avicebron 17 hours ago
based, move on.
reply
jamesjyu 14 hours ago
Next up: using Chipotle AI to solve Erdős problems
reply
stronglikedan 17 hours ago
and they say the hardest thing in software is naming things, pffft...
reply
xrd 6 hours ago
TL;DR: this is a 23B model, and in this case the B stands for "pinto beans."
reply
vladsiu 14 hours ago
[dead]
reply
simonsarris 17 hours ago
reminiscent of when people were trying to mine bitcoin in the background of web pages, or with more trad malware
reply