Apparently Chipotle is not alone with AI embedded into their solutions which willingly answers questions far outside its expected remit.
Though amusing, this provides a potential attack vector into Lucid itself: the lack of prompt validating/sanitizing is as potentially damaging as SQL Injection, present in OWASP‘s Top-10 list since the initial 2003 Top-10 publication. Could an interface be created which integrates your IDE with Lucid to process prompts? Could Lucid be taken off-line or even bankrupted by a competitor sending large volumes of expensive prompts through Lucid’s AI dialog? Could Lucid intellectual property be exposed? Without restricting the AI to Lucid-specific activity, all bets are off.
I’ll bet that Lucid’s software engineers used AI to implement the embedded AI functionality and approved the PRs without any comprehension of the code generated. Ah, the joys of artificial intelligence ….






