<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AI 에이전트 &#8211; WONIZZ.LOG</title>
	<atom:link href="https://blog.wonizz.com/tag/ai-%ec%97%90%ec%9d%b4%ec%a0%84%ed%8a%b8/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.wonizz.com</link>
	<description>AI 자동화를 직접 굴려 본 개발자의 실무 교훈</description>
	<lastBuildDate>Mon, 28 Sep 2026 14:28:46 +0000</lastBuildDate>
	<language>ko-KR</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/08/wz-siteicon-512.png?fit=32%2C32&#038;ssl=1</url>
	<title>AI 에이전트 &#8211; WONIZZ.LOG</title>
	<link>https://blog.wonizz.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">152411368</site>	<item>
		<title>[AI Now] 그록봇 가격, 300달러 말고 3가지</title>
		<link>https://blog.wonizz.com/2026/09/03/grok-bot-price-paths/</link>
					<comments>https://blog.wonizz.com/2026/09/03/grok-bot-price-paths/#respond</comments>
		
		<dc:creator><![CDATA[워니즈]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 00:24:06 +0000</pubDate>
				<category><![CDATA[AI Now]]></category>
		<category><![CDATA[AI 에이전트]]></category>
		<category><![CDATA[Cursor]]></category>
		<category><![CDATA[Grok Bot]]></category>
		<category><![CDATA[xAI]]></category>
		<category><![CDATA[그록봇]]></category>
		<category><![CDATA[요금제]]></category>
		<guid isPermaLink="false">https://blog.wonizz.com/2026/09/03/grok-bot-price-paths/</guid>

					<description><![CDATA[<p>The standard Lorem Ipsum passage, used since the 1500s<br />
"Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum."</p>
<p>Section 1.10.32 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"Sed ut perspiciatis unde omnis iste natus error sit voluptatem accusantium doloremque laudantium, totam rem aperiam, eaque ipsa quae ab illo inventore veritatis et quasi architecto beatae vitae dicta sunt explicabo. Nemo enim ipsam voluptatem quia voluptas sit aspernatur aut odit aut fugit, sed quia consequuntur magni dolores eos qui ratione voluptatem sequi nesciunt. Neque porro quisquam est, qui dolorem ipsum quia dolor sit amet, consectetur, adipisci velit, sed quia non numquam eius modi tempora incidunt ut labore et dolore magnam aliquam quaerat voluptatem. Ut enim ad minima veniam, quis nostrum exercitationem ullam corporis suscipit laboriosam, nisi ut aliquid ex ea commodi consequatur? Quis autem vel eum iure reprehenderit qui in ea voluptate velit esse quam nihil molestiae consequatur, vel illum qui dolorem eum fugiat quo voluptas nulla pariatur?"</p>
<p>1914 translation by H. Rackham<br />
"But I must explain to you how all this mistaken idea of denouncing pleasure and praising pain was born and I will give you a complete account of the system, and expound the actual teachings of the great explorer of the truth, the master-builder of human happiness. No one rejects, dislikes, or avoids pleasure itself, because it is pleasure, but because those who do not know how to pursue pleasure rationally encounter consequences that are extremely painful. Nor again is there anyone who loves or pursues or desires to obtain pain of itself, because it is pain, but because occasionally circumstances occur in which toil and pain can procure him some great pleasure. To take a trivial example, which of us ever undertakes laborious physical exercise, except to obtain some advantage from it? But who has any right to find fault with a man who chooses to enjoy a pleasure that has no annoying consequences, or one who avoids a pain that produces no resultant pleasure?"</p>
<p>Section 1.10.33 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"At vero eos et accusamus et iusto odio dignissimos ducimus qui blanditiis praesentium voluptatum deleniti atque corrupti quos dolores et quas molestias excepturi sint occaecati cupiditate non provident, similique sunt in culpa qui officia deserunt mollitia animi, id est laborum et dolorum fuga. Et harum quidem rerum facilis est et expedita distinctio. Nam libero tempore, cum soluta nobis est eligendi optio cumque nihil impedit quo minus id quod maxime placeat facere possimus, omnis voluptas assumenda est, omnis dolor repellendus. Temporibus autem quibusdam et aut officiis debitis aut rerum necessitatibus saepe eveniet ut et voluptates repudiandae sint et molestiae non recusandae. Itaque earum rerum hic tenetur a sapiente delectus, ut aut reiciendis voluptatibus maiores alias consequatur aut perferendis doloribus asperiores repellat."</p>
<p>1914 translation by H. Rackham<br />
"On the other hand, we denounce with righteous indignation and dislike men who are so beguiled and demoralized by the charms of pleasure of the moment, so blinded by desire, that they cannot foresee the pain and trouble that are bound to ensue; and equal blame belongs to those who fail in their duty through weakness of will, which is the same as saying through shrinking from toil and pain. These cases are perfectly simple and easy to distinguish. In a free hour, when our power of choice is untrammelled and when nothing prevents our being able to do what we like best, every pleasure is to be welcomed and every pain avoided. But in certain circumstances and owing to the claims of duty or the obligations of business it will frequently occur that pleasures have to be repudiated and annoyances accepted. The wise man therefore always holds in these matters to this principle of selection: he rejects pleasures to secure other greater pleasures, or else he endures pains to avoid worse pains."</p>
<p>그록봇 가격을 검색하면 월 300달러 이야기만 나오지만, 공개 원문에는 개인 월 200달러와 좌석당 월 120달러 경로가 함께 적혀 있습니다. 세 갈래를 표로 비교하고, 요금제가 겹쳐 중복 결제가 나는 구간과 결제 전에 확인할 순서까지 정리했습니다.</p>
<p>The post <a rel="nofollow" href="https://blog.wonizz.com/2026/09/03/grok-bot-price-paths/">[AI Now] 그록봇 가격, 300달러 말고 3가지</a> appeared first on <a rel="nofollow" href="https://blog.wonizz.com">WONIZZ.LOG</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The standard Lorem Ipsum passage, used since the 1500s<br />
"Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum."</p>
<p>Section 1.10.32 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"Sed ut perspiciatis unde omnis iste natus error sit voluptatem accusantium doloremque laudantium, totam rem aperiam, eaque ipsa quae ab illo inventore veritatis et quasi architecto beatae vitae dicta sunt explicabo. Nemo enim ipsam voluptatem quia voluptas sit aspernatur aut odit aut fugit, sed quia consequuntur magni dolores eos qui ratione voluptatem sequi nesciunt. Neque porro quisquam est, qui dolorem ipsum quia dolor sit amet, consectetur, adipisci velit, sed quia non numquam eius modi tempora incidunt ut labore et dolore magnam aliquam quaerat voluptatem. Ut enim ad minima veniam, quis nostrum exercitationem ullam corporis suscipit laboriosam, nisi ut aliquid ex ea commodi consequatur? Quis autem vel eum iure reprehenderit qui in ea voluptate velit esse quam nihil molestiae consequatur, vel illum qui dolorem eum fugiat quo voluptas nulla pariatur?"</p>
<p>1914 translation by H. Rackham<br />
"But I must explain to you how all this mistaken idea of denouncing pleasure and praising pain was born and I will give you a complete account of the system, and expound the actual teachings of the great explorer of the truth, the master-builder of human happiness. No one rejects, dislikes, or avoids pleasure itself, because it is pleasure, but because those who do not know how to pursue pleasure rationally encounter consequences that are extremely painful. Nor again is there anyone who loves or pursues or desires to obtain pain of itself, because it is pain, but because occasionally circumstances occur in which toil and pain can procure him some great pleasure. To take a trivial example, which of us ever undertakes laborious physical exercise, except to obtain some advantage from it? But who has any right to find fault with a man who chooses to enjoy a pleasure that has no annoying consequences, or one who avoids a pain that produces no resultant pleasure?"</p>
<p>Section 1.10.33 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"At vero eos et accusamus et iusto odio dignissimos ducimus qui blanditiis praesentium voluptatum deleniti atque corrupti quos dolores et quas molestias excepturi sint occaecati cupiditate non provident, similique sunt in culpa qui officia deserunt mollitia animi, id est laborum et dolorum fuga. Et harum quidem rerum facilis est et expedita distinctio. Nam libero tempore, cum soluta nobis est eligendi optio cumque nihil impedit quo minus id quod maxime placeat facere possimus, omnis voluptas assumenda est, omnis dolor repellendus. Temporibus autem quibusdam et aut officiis debitis aut rerum necessitatibus saepe eveniet ut et voluptates repudiandae sint et molestiae non recusandae. Itaque earum rerum hic tenetur a sapiente delectus, ut aut reiciendis voluptatibus maiores alias consequatur aut perferendis doloribus asperiores repellat."</p>
<p>1914 translation by H. Rackham<br />
"On the other hand, we denounce with righteous indignation and dislike men who are so beguiled and demoralized by the charms of pleasure of the moment, so blinded by desire, that they cannot foresee the pain and trouble that are bound to ensue; and equal blame belongs to those who fail in their duty through weakness of will, which is the same as saying through shrinking from toil and pain. These cases are perfectly simple and easy to distinguish. In a free hour, when our power of choice is untrammelled and when nothing prevents our being able to do what we like best, every pleasure is to be welcomed and every pain avoided. But in certain circumstances and owing to the claims of duty or the obligations of business it will frequently occur that pleasures have to be repudiated and annoyances accepted. The wise man therefore always holds in these matters to this principle of selection: he rejects pleasures to secure other greater pleasures, or else he endures pains to avoid worse pains."</p>
<p>안녕하세요? 정리하는 개발자 워니즈입니다.</p>
<p>그록봇을 한번 써보려면 정말로 매달 300달러라는 금액을 감당해야만 하는 것일까요?</p>
<p>이 글은 그록봇 가격 이야기가 어쩌다 월 300달러라는 숫자 하나로만 굳어져 버렸는지를 짚어보고, 제품이 공개될 때 함께 적혀 있었던 나머지 두 갈래를 같은 자리에 놓고 비교해서, 읽는 분이 자기 상황에서 어느 경로를 골라야 하는지 스스로 판단할 수 있도록 정리하는 글입니다.</p>
<p><strong>【한 줄 요약】</strong></p>
<ul>
<li>그록봇에 접근하는 경로는 하나가 아니라 셋이고, 공개 원문 기준으로 개인이 쓰는 Cursor Ultra는 월 200달러, 팀 단위로 쓰는 Cursor Premium Teams는 좌석당 월 120달러, 그리고 가장 널리 알려진 SuperGrok Heavy가 월 300달러입니다.</li>
<li>그록봇 가격을 다루는 한국어 콘텐츠 상당수가 세 번째 경로만 이야기하고 있어서, 팀으로 쓰면 좌석당 120달러로 내려간다는 사실이 검색하는 분들에게 잘 전달되지 않고 있습니다.</li>
<li>요금제가 두 계열로 나뉘어 운영되면서 겹치는 구간이 생기기 때문에, 확인 없이 결제하면 같은 것을 쓰면서 돈만 더 내는 일이 생길 수 있고 그래서 결제 직전에 공식 화면을 다시 보는 절차가 필요합니다.</li>
</ul>
<p><strong>목차</strong></p>
<ol>
<li>그록봇은 무엇이고 무엇을 하는 도구인가</li>
<li>왜 그록봇 가격이 300달러 하나로만 알려졌을까?</li>
<li>첫 번째 경로, 개인이 쓰는 Cursor Ultra 월 200달러</li>
<li>두 번째 경로, 팀이 쓰는 Cursor Premium Teams 좌석당 월 120달러</li>
<li>세 번째 경로, SuperGrok Heavy 월 300달러</li>
<li>세 경로를 한 표에 놓고 비교하면</li>
<li>SuperGrok 계열과 Premium 계열은 왜 겹치고 어디서 돈이 새는가?</li>
<li>그록봇 가격에서 안 되는 것과 확인하지 못한 것</li>
<li>내 상황에 맞는 경로를 고르는 순서</li>
<li>정리, 누구에게 맞고 누구에게는 굳이인가<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/09/gb-01-three-paths.png?w=1200&#038;ssl=1" alt="그록봇 가격 세 갈래 경로와 월 비용 비교" />
  </li>
</ol>
<hr />
<h2>1. 그록봇은 무엇이고 무엇을 하는 도구인가</h2>
<p>그록봇은 2026년 8월 13일에 공개된 xAI의 에이전트형 제품인데요, 가격 이야기를 시작하기 전에 이 도구가 애초에 무엇을 하는 물건인지부터 정리하고 넘어가는 편이 판단에 도움이 될 것 같습니다. 공개 당시 소개된 정의를 그대로 옮기면, 동료에게 지시하듯 업무를 맡기면 프로젝트를 처음부터 끝까지 수행하고 승인이 필요할 때 사용자에게 돌아오는 AI 팀원이라고 설명되어 있습니다.</p>
<p>여기서 눈여겨볼 표현이 두 개 있습니다. 하나는 처음부터 끝까지 수행한다는 부분이고, 다른 하나는 승인이 필요할 때 돌아온다는 부분인데요, 이 둘을 붙여서 읽으면 이 제품이 매 단계마다 사람의 확인을 받는 구조가 아니라 스스로 판단해서 이어가다가 필요한 순간에만 사람을 부르는 구조라는 뜻이 됩니다. 실제로 공개 원문에는 사용자가 모든 단계를 승인하지 않아도 다음 행동을 이어간다는 설명이 명시되어 있습니다.</p>
<p>여러 개의 봇을 동시에 배치할 수 있다는 점도 원문에 적혀 있는 특징입니다. 같은 스레드 안에서 봇들이 서로 작업을 넘겨줄 수 있고, 프로젝트 업무와 아웃바운드 업무와 시스템 업무를 24시간 병렬로 처리한다는 설명이 함께 붙어 있는데요, 이 병렬성이라는 성질이 나중에 요금제를 이해할 때 중요한 실마리가 되니 기억해 두시면 좋겠습니다. 지원 플랫폼은 데스크톱과 iOS 두 가지로 안내되어 있습니다.<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/09/gb-02-flow.png?w=1200&#038;ssl=1" alt="그록봇이 업무를 자동으로 진행하는 흐름" /><br />
승인을 매번 받지 않고 다음 행동을 이어가는 구조라는 점은 편리함인 동시에 사전에 이해해 두어야 할 성질이기도 합니다. 이 구조를 왜 조심스럽게 다뤄야 하는지는 <a href="https://blog.wonizz.com/2026/09/02/claude-code-prompt-injection/">승인 없이 다음 단계를 이어가는 구조의 위험</a>을 다룬 이전 글에서 다른 도구를 예로 들어 정리해 둔 적이 있습니다. 자동 진행이라는 성질 자체가 마음에 걸리시는 분이라면 결제 판단과 별개로 한 번 훑어보셔도 좋을 것 같습니다.</p>
<h2>2. 왜 그록봇 가격이 300달러 하나로만 알려졌을까?</h2>
<p>한국어로 그록봇 가격이나 그록봇 요금제를 검색해 보면 상위에 노출되는 글 대부분이 SuperGrok Heavy 월 300달러라는 숫자를 중심에 놓고 설명합니다. 유튜브 쪽도 사정이 비슷해서, 공개 나흘 뒤인 8월 17일에 올라온 영상 제목이 아예 월 300달러 그록봇이 돈값을 하는지 묻는 형태로 되어 있을 정도입니다. 그러니까 검색해서 들어오는 사람 입장에서는 그록봇 가격이 곧 300달러라는 인상을 받게 되는 것이 자연스럽습니다.</p>
<p>그런데 공개 원문을 열어보면 접근 경로가 하나가 아닙니다. 원문에는 SuperGrok Heavy 외에 Cursor Ultra와 Cursor Premium Teams라는 두 개의 경로가 함께 명시되어 있습니다. 두 경로 모두 300달러보다 낮은 금액인데요, 특히 팀 단위 요금은 좌석당 월 120달러로 SuperGrok Heavy의 절반에도 미치지 않습니다. 이 정보가 한국어 콘텐츠에서 잘 다뤄지지 않으면서 그록봇 가격을 보는 시각이 한쪽으로 쏠린 것으로 보입니다.</p>
<p>왜 이런 쏠림이 생겼는지는 추측의 영역이라 단정하기 어렵습니다만, 300달러라는 숫자가 유독 눈에 띄는 크기라서 제목으로 뽑기 좋았다는 점과, SuperGrok이라는 이름이 이미 알려져 있어서 설명하기 편했다는 점은 짐작해 볼 수 있을 것 같습니다. 어느 쪽이든 결과적으로는 더 저렴한 경로가 있다는 사실이 가려졌고, 그 부분이 이 글에서 채우려는 자리입니다.</p>
<p>콘텐츠가 적어서 생긴 공백은 아니라는 점도 짚어두고 싶습니다. 공개 시점부터 이 글을 쓰는 시점까지 약 3주 사이에 한국어 유튜브 영상만 다섯 편이 올라왔고, 설치와 활용 방법을 다룬 총정리 영상이 8월 19일에, 교육자를 대상으로 한 설명 영상이 8월 22일에, 여러 AI와 단체 대화를 하는 사용법 영상이 8월 29일에 각각 공개되었습니다. 국내 기술 커뮤니티 쪽에서도 8월 13일 공개 소식과 8월 14일 모델 관련 소식에 이어 9월 1일에는 이 도구로 엔지니어링 조직을 운영한 사례까지 올라왔으니, 관심의 총량은 결코 적지 않았던 셈입니다.</p>
<p>그러니까 그록봇 가격에 관한 정보가 부족했던 것이 아니라, 여러 사람이 같은 숫자 하나를 반복해서 다루는 동안 나머지 두 갈래가 다뤄지지 않은 채로 남아 있었다고 보는 편이 정확할 것 같습니다. 검색 결과 상위 몇 개를 훑고 판단을 끝내면 놓치게 되는 정보가 바로 이런 종류인데요, 금액 차이가 매달 100달러 이상이니 한 번쯤 원문을 열어볼 가치는 충분하다고 생각합니다.<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/09/gb-03-known-vs-actual.png?w=1200&#038;ssl=1" alt="널리 알려진 그록봇 가격과 원문에 함께 적힌 경로의 차이" /><br />
여기서 한 가지 분명히 하고 시작하겠습니다. 필자는 그록봇을 결제한 적도 없고 실제로 실행해 본 적도 없습니다. 그래서 이 글에는 잘 돌아간다거나 답답하다거나 하는 사용 감상이 한 줄도 들어 있지 않고, 대신 공개된 원문과 검색으로 확인 가능한 요금 정보만 다룹니다. 아래에 나오는 요금표 역시 검색 결과를 인용한 것이지 필자가 결제 화면에서 직접 확인한 값이 아니라는 점을 미리 밝혀 둡니다.</p>
<h2>3. 첫 번째 경로, 개인이 쓰는 Cursor Ultra 월 200달러</h2>
<p>첫 번째 경로는 Cursor Ultra 요금제로 접근하는 방식이고 금액은 월 200달러입니다. 개인 사용자를 대상으로 하는 요금제이기 때문에 혼자 일하는 분이나 팀 계정을 만들 상황이 아닌 분에게 해당하는 경로인데요, SuperGrok Heavy와 비교하면 매달 100달러를 덜 내는 셈이 되고 1년으로 환산하면 1,200달러 차이가 납니다.</p>
<p>이 경로가 그록봇 가격을 이야기할 때 특히 중요한 이유는 조건이 단순하기 때문입니다. 팀을 꾸릴 필요도 없고 좌석 수를 계산할 필요도 없이 개인 구독 하나로 정리되기 때문에, 일단 이 도구가 내 업무에 맞는지부터 확인하고 싶은 단계에 있는 분이라면 검토 대상 1순위에 놓을 만한 선택지입니다.</p>
<p>다만 주의할 점이 있습니다. 원문이 알려주는 것은 이 요금제로 접근할 수 있다는 사실이고, 그 안에서 사용량이 어떻게 제한되는지, 동시에 몇 개의 봇을 돌릴 수 있는지 같은 세부 조건까지 알려주지는 않습니다. 뒤에서 다시 다루겠지만 동시 실행 봇 수의 상한은 원문에 적혀 있지 않기 때문에, 이 부분을 근거 없이 짐작해서 계획을 세우는 것은 피하시는 편이 좋겠습니다.</p>
<h2>4. 두 번째 경로, 팀이 쓰는 Cursor Premium Teams 좌석당 월 120달러</h2>
<p>두 번째 경로는 Cursor Premium Teams이고 금액은 좌석당 월 120달러입니다. 세 갈래 중 1인당 부담이 가장 낮은 경로인데요, 좌석당이라는 단서가 붙어 있으므로 인원이 늘어나면 총액도 함께 늘어난다는 점은 계산할 때 반드시 반영해야 합니다.</p>
<p>숫자로 감을 잡아보면 이렇습니다. 혼자서 SuperGrok Heavy를 쓰면 월 300달러이고, 같은 금액으로 팀 요금제를 쓴다면 좌석 두 개를 채우고도 60달러가 남습니다. 세 명이 함께 쓰면 총액이 360달러가 되어 SuperGrok Heavy 한 명분보다 60달러 더 나가는 정도이니, 팀 단위로 도입을 검토하는 조직 입장에서는 그록봇 가격 구조가 생각보다 부담스럽지 않게 느껴질 수 있는 지점입니다.</p>
<p>1년 단위로 환산해 보면 차이가 조금 더 뚜렷하게 보입니다. 좌석 세 개를 1년간 유지하면 총액이 4,320달러이고, 같은 세 사람이 각자 SuperGrok Heavy를 결제한다면 10,800달러가 되어 6,480달러의 격차가 생깁니다. 물론 두 상품이 제공하는 범위가 완전히 같지는 않으므로 이 숫자를 그대로 절감액이라고 부를 수는 없습니다만, 그록봇 가격을 인원수와 기간까지 넣어 계산해 보면 경로 선택이 단순한 취향 문제가 아니라는 점은 분명해집니다.</p>
<p>물론 여기에는 전제가 있습니다. 팀 요금제는 이름 그대로 팀 계정을 전제로 하기 때문에 결제 주체와 관리 권한이 개인 구독과 다르게 잡히고, 좌석을 늘리거나 줄이는 절차도 개인 요금제보다 복잡합니다. 회사에서 도입한다면 결제 카드 소유자와 좌석 관리자를 누가 맡을지, 사람이 나갔을 때 좌석을 어떻게 회수할지 같은 운영 문제가 따라옵니다. 이런 항목은 요금표만 봐서는 보이지 않으니 도입 전 확인 목록을 만들어 두는 편이 안전합니다.</p>
<p>도구를 팀에 들이기 전에 무엇을 확인해야 하는지 궁금하시다면 <a href="https://blog.wonizz.com/2026/08/31/claude-code-plugin-checklist/">설치와 도입 전에 짚고 넘어갈 항목들</a>을 정리해 둔 글이 있으니 참고하셔도 좋겠습니다. 대상 도구는 다르지만 확인해야 할 항목의 성격은 상당 부분 겹칩니다.<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/09/gb-04-solo-vs-team.png?w=1200&#038;ssl=1" alt="혼자 쓸 때와 팀으로 쓸 때의 1인당 그록봇 가격" /></p>
<h2>5. 세 번째 경로, SuperGrok Heavy 월 300달러</h2>
<p>세 번째 경로는 가장 널리 알려진 SuperGrok Heavy이고 금액은 월 300달러입니다. 그런데 이 경로에는 다른 두 경로에 없는 조건이 하나 붙어 있는데요, 공개 원문에 따르면 기존 SuperGrok Heavy 사용자에게는 그록봇이 요금제에 포함되는 형태로 제공됩니다. 그러니까 이미 이 요금제를 쓰고 있던 분이라면 추가로 지불할 금액 없이 접근할 수 있다는 뜻이 됩니다.</p>
<p>이 조건 때문에 세 번째 경로는 두 부류로 나뉩니다. 이미 SuperGrok Heavy를 구독 중인 분에게는 사실상 추가 비용이 0달러인 가장 저렴한 경로가 되고, 지금 아무것도 구독하고 있지 않은 분에게는 세 경로 중 가장 비싼 선택지가 됩니다. 같은 요금제인데 출발점에 따라 정반대의 평가를 받는 셈이라, 그록봇 가격을 검토할 때는 요금표를 보기 전에 내가 지금 무엇을 결제하고 있는지부터 확인하는 순서가 맞습니다.</p>
<blockquote><p>같은 요금제가 출발점에 따라 가장 저렴한 경로도 되고 가장 비싼 선택지도 됩니다.</p>
</blockquote>
<p>SuperGrok 요금제 자체는 아래와 같은 계단 구조로 알려져 있습니다. 다시 강조드리면 이 표는 검색 결과를 인용한 것이고 필자가 결제 화면에서 확인한 값이 아니므로, 결제하시기 전에는 반드시 공식 화면에서 다시 확인해 주시기 바랍니다.</p>
<figure class="wp-block-table">
<table>
<thead>
<tr>
<th>플랜</th>
<th>월 가격</th>
<th>알려진 조건</th>
</tr>
</thead>
<tbody>
<tr>
<td>무료</td>
<td>0달러</td>
<td>2시간에 10회, 이미지는 하루 3회</td>
</tr>
<tr>
<td>SuperGrok Lite</td>
<td>10달러</td>
<td>유료 진입 단계</td>
</tr>
<tr>
<td>SuperGrok</td>
<td>30달러</td>
<td>표준 유료 단계</td>
</tr>
<tr>
<td>SuperGrok Heavy</td>
<td>300달러</td>
<td>그록봇이 요금제에 포함</td>
</tr>
</tbody>
</table>
</figure>
<p>30달러에서 300달러로 열 배가 뛰는 계단을 보면 그 위 단계가 뭐가 그렇게 다른지 궁금해지실 것입니다. 이 계단을 놓고 Heavy의 실체가 더 똑똑한 모델이라기보다 한도와 병렬성에 가깝다고 보는 분석이 있습니다. 앞에서 그록봇이 여러 봇을 24시간 병렬로 돌리는 제품이라고 설명드렸던 부분과 이어지는 이야기입니다. 다만 이것은 분석이지 공식 설명이 아니므로 사실로 받아들이시면 곤란하고, 참고 정보 정도로만 두시는 것이 맞겠습니다.<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/09/gb-05-definition.png?w=1200&#038;ssl=1" alt="공개 원문에 적힌 그록봇의 정의" /></p>
<h2>6. 세 경로를 한 표에 놓고 비교하면</h2>
<p>지금까지 나온 세 갈래를 하나의 표로 모으면 다음과 같습니다. 표를 볼 때는 금액만 보지 마시고 오른쪽 두 열을 함께 보시는 것이 좋은데요, 같은 금액이라도 대상과 조건이 다르면 나에게 맞는지 여부가 달라지기 때문입니다.</p>
<figure class="wp-block-table">
<table>
<thead>
<tr>
<th>경로</th>
<th>월 비용</th>
<th>주로 맞는 대상</th>
<th>함께 볼 조건</th>
</tr>
</thead>
<tbody>
<tr>
<td>Cursor Ultra</td>
<td>200달러</td>
<td>개인 사용자</td>
<td>개인 구독이라 절차가 단순</td>
</tr>
<tr>
<td>Cursor Premium Teams</td>
<td>좌석당 120달러</td>
<td>팀 또는 조직</td>
<td>인원수만큼 총액이 늘어남</td>
</tr>
<tr>
<td>SuperGrok Heavy</td>
<td>300달러</td>
<td>기존 구독자 또는 개인</td>
<td>기존 사용자는 요금제에 포함</td>
</tr>
</tbody>
</table>
</figure>
<p>표를 이렇게 놓고 보면 1인당 금액만으로는 순위가 팀 요금제, 개인 요금제, SuperGrok Heavy 순이 되지만, 이미 SuperGrok Heavy를 쓰고 있는 분에게는 추가 지출이 발생하지 않으므로 그 분에게는 순위가 완전히 뒤집힙니다. 그록봇 가격을 남의 글에서 읽은 숫자 하나로 판단하면 안 되는 이유가 여기에 있습니다.</p>
<p>한 가지 더 짚어둘 것은 세 경로가 서로 다른 제품 안에 들어 있다는 사실입니다. 앞의 두 경로는 Cursor라는 제품의 요금제이고 마지막 하나는 xAI 쪽 요금제인데요, 그래서 어느 경로를 고르느냐에 따라 함께 딸려오는 기능과 결제 창구가 달라집니다. 그록봇만 놓고 비교하면 금액 차이로 보이지만, 실제로는 서로 다른 제품을 결제하면서 그 안에서 같은 기능에 접근하는 구조라는 점을 감안하셔야 합니다.</p>
<h2>7. SuperGrok 계열과 Premium 계열은 왜 겹치고 어디서 돈이 새는가?</h2>
<p>이 질문이 이 글에서 가장 실용적인 부분이라고 생각합니다. 답을 먼저 말씀드리면, grok.com 쪽에서 운영되는 SuperGrok 계열과 X 서비스에 묶여 있는 Premium 계열이 별도로 운영되면서 제공 범위가 일부 겹치기 때문에, 어느 쪽을 결제해야 하는지 모른 채 양쪽을 다 결제하거나 잘못된 쪽을 결제하면 같은 것을 쓰면서 돈만 더 내는 상황이 생길 수 있습니다.</p>
<p>구조를 조금 풀어보면 이렇습니다. 하나는 AI 서비스 자체를 파는 구독이고 다른 하나는 소셜 서비스의 유료 등급에 AI 기능이 얹혀 있는 형태인데요, 출발점이 다른 두 상품이 시간이 지나면서 기능이 겹치는 구간을 갖게 된 것입니다. 사용자 입장에서는 이름도 비슷하고 접근 경로도 비슷해 보이니 어느 쪽이 내가 원하는 것인지 판단하기가 쉽지 않습니다.</p>
<p>그래서 그록봇 가격을 확정하기 전에 다음 순서를 밟으시길 권합니다. 첫째로 지금 내 계정에서 이미 결제되고 있는 구독이 무엇인지 확인합니다. 둘째로 그 구독이 어느 계열에 속하는지, 즉 AI 서비스 쪽인지 소셜 서비스 유료 등급 쪽인지 구분합니다. 셋째로 내가 필요한 기능이 이미 결제 중인 구독에 포함되어 있는지 확인하고, 그다음에야 추가 결제 여부를 판단합니다. 이 세 단계를 건너뛰면 중복 결제가 발생할 여지가 그대로 남습니다.<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/09/gb-06-check-order.png?w=1200&#038;ssl=1" alt="중복 결제를 피하는 확인 순서 세 단계" /><br />
프로모션도 같은 맥락에서 조심하실 필요가 있습니다. 할인 정보가 돌아다니는 것을 보실 수 있는데요, 프로모션 가격은 계정과 지역과 조회 시점에 따라 달라지기 때문에 어떤 글에 적힌 할인율이 내 화면에서도 똑같이 적용된다는 보장이 없습니다. 그러니 남이 정리해 둔 할인 금액을 기준으로 예산을 잡지 마시고, 결제 직전에 공식 결제 화면에서 표시되는 금액을 다시 확인하신 뒤에 진행하시기 바랍니다. 이 확인을 빠뜨리면 예상과 다른 금액이 청구될 수 있습니다.</p>
<h2>8. 그록봇 가격에서 안 되는 것과 확인하지 못한 것</h2>
<p>이 절은 이 글이 하지 못하는 것을 적는 자리입니다. 알아낸 것만 적고 알아내지 못한 것을 숨기면 읽는 분이 잘못된 확신을 갖게 되기 때문에, 경계를 분명히 그어두는 편이 낫다고 생각합니다.</p>
<figure class="wp-block-table">
<table>
<thead>
<tr>
<th>항목</th>
<th>상태</th>
<th>설명</th>
</tr>
</thead>
<tbody>
<tr>
<td>세 경로의 존재와 금액</td>
<td>확인함</td>
<td>공개 원문에 명시된 내용</td>
</tr>
<tr>
<td>SuperGrok 요금 계단</td>
<td>인용함</td>
<td>검색 결과 인용이며 결제 화면 확인은 아님</td>
</tr>
<tr>
<td>동시 실행 봇 수 상한</td>
<td>확인 못 함</td>
<td>원문에 수치가 없음</td>
</tr>
<tr>
<td>명시적 제한사항</td>
<td>확인 못 함</td>
<td>원문에 별도 항목이 없음</td>
</tr>
<tr>
<td>실제 동작과 성능</td>
<td>확인 못 함</td>
<td>결제하지 않았고 실행해 보지 않음</td>
</tr>
<tr>
<td>프로모션 적용 금액</td>
<td>확인 불가</td>
<td>계정과 지역과 시점에 따라 달라짐</td>
</tr>
</tbody>
</table>
</figure>
<p>먼저 안 되는 것부터 말씀드리면, 이 글로는 그록봇이 실제로 얼마나 쓸 만한지를 판단하실 수 없습니다. 필자가 결제하지 않았고 실행해 보지 않았기 때문에 동작이나 성능을 두고 쓸 수 있는 내용이 아예 없습니다. 이 글이 도와드릴 수 있는 범위는 어느 경로가 내 상황에 맞는지를 고르는 데까지이고, 그 도구가 값어치를 하는지는 별도의 판단이 필요합니다.</p>
<p>동시 실행 봇 수의 상한도 확인하지 못한 항목입니다. 원문은 여러 봇을 동시에 배치해 24시간 병렬로 처리한다고만 설명하고 몇 개까지 가능한지는 적어두지 않았는데요, 그래서 몇 개까지 된다는 식의 숫자를 이 글에 쓰지 않았습니다. 다른 글에서 구체적인 숫자를 보시거든 그 숫자가 어디서 나온 것인지 출처를 한 번 확인해 보시길 권합니다.</p>
<p>한 가지 참고할 만한 이야기는 공개 원문 댓글에서 나온 우려입니다. 상시로 실행되는 에이전트는 엄청난 토큰을 소비한다는 지적이었는데요, 이것은 공식 설명이 아니라 읽는 사람의 우려이므로 사실로 취급하시면 안 되지만, 요금제 안에서 한도가 어떻게 걸리는지를 미리 확인해 볼 이유는 된다고 생각합니다. 24시간 병렬이라는 표현과 한도라는 개념은 결국 어느 지점에서 만나기 마련입니다.</p>
<h2>9. 내 상황에 맞는 경로를 고르는 순서</h2>
<p>지금까지의 내용을 실제 판단으로 옮기면 아래 표처럼 정리됩니다. 표에 있는 추천은 금액과 조건만 놓고 계산한 결과이고 제품의 만족도를 반영한 것이 아니라는 점을 다시 말씀드립니다.</p>
<figure class="wp-block-table">
<table>
<thead>
<tr>
<th>내 상황</th>
<th>우선 볼 경로</th>
<th>이유</th>
</tr>
</thead>
<tbody>
<tr>
<td>이미 SuperGrok Heavy 구독 중</td>
<td>그대로 사용</td>
<td>요금제에 포함되어 추가 지출 없음</td>
</tr>
<tr>
<td>혼자 쓰고 아무 구독도 없음</td>
<td>Cursor Ultra</td>
<td>개인 대상 200달러로 절차가 단순</td>
</tr>
<tr>
<td>세 명 이상이 함께 사용</td>
<td>Cursor Premium Teams</td>
<td>좌석당 120달러로 1인당 부담이 가장 낮음</td>
</tr>
<tr>
<td>일단 감만 잡고 싶음</td>
<td>결제 보류</td>
<td>무료 등급과 저가 도구로 먼저 확인</td>
</tr>
</tbody>
</table>
</figure>
<p>마지막 행이 왜 필요한지 말씀드리면, 매달 100달러가 넘는 금액을 감으로 결제하는 것은 아무래도 부담스러운 선택입니다. 에이전트가 업무를 대신 처리한다는 방식 자체가 나에게 맞는지부터 확인하고 싶은 단계라면, 무료나 저비용으로 접근할 수 있는 도구로 먼저 성격을 파악해 보는 것도 방법인데요, 그런 경로에 관심이 있으시다면 <a href="https://blog.wonizz.com/2026/08/29/glm-5-3-flash-free-usage/">무료 등급으로 모델을 먼저 써보는 방법</a>을 정리한 글이 도움이 되실 수 있습니다.</p>
<p>고르는 순서를 문장으로 다시 적어보면 이렇습니다. 지금 결제 중인 구독을 먼저 확인하고, 혼자 쓸지 팀으로 쓸지를 정하고, 인원수를 반영해 총액을 계산한 다음, 결제 직전에 공식 화면에서 금액을 다시 확인합니다. 이 순서를 지키면 적어도 중복 결제나 예상 밖 청구는 피하실 수 있을 것 같습니다.<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/09/gb-07-decide-order.png?w=1200&#038;ssl=1" alt="내 상황에 맞는 그록봇 가격 경로를 고르는 순서" /></p>
<h2>10. 정리, 누구에게 맞고 누구에게는 굳이인가</h2>
<p>정리하겠습니다. 그록봇 가격은 월 300달러 하나가 아니라 세 갈래이고, 개인은 월 200달러인 Cursor Ultra로, 팀은 좌석당 월 120달러인 Cursor Premium Teams로 접근할 수 있으며, 이미 SuperGrok Heavy를 쓰고 있던 분은 요금제에 포함된 형태로 추가 지출 없이 쓸 수 있습니다. 검색 상위 콘텐츠 대부분이 세 번째 경로만 이야기하고 있어서 이 구분이 잘 전달되지 않고 있는데, 잘못 고르면 매달 100달러 이상을 더 내게 되는 차이입니다.</p>
<p>누구에게 맞는지를 말씀드리면, 여러 건의 업무를 동시에 굴려야 하고 그 업무들이 사람의 매 단계 확인 없이도 진행될 만한 성격이라면 검토해 볼 가치가 있는 도구로 보입니다. 반대로 단계마다 사람이 확인해야 하는 성격의 업무가 대부분이라면 자동 진행이라는 이 제품의 핵심 성질이 오히려 부담이 될 수 있으니, 그런 경우에는 굳이 서두르실 필요가 없다고 생각합니다.</p>
<p>한 가지 덧붙이면, 이 판단은 요금이 바뀌면 다시 해야 하는 종류의 판단입니다. 세 경로가 서로 다른 회사의 서로 다른 제품에 걸쳐 있기 때문에 어느 한쪽의 요금 정책이 조정되면 순위가 뒤집힐 수 있고, 지금 가장 저렴한 경로가 몇 달 뒤에도 가장 저렴하다는 보장은 없습니다. 그래서 이 글도 오늘 시점의 그록봇 가격을 정리한 것이지 앞으로도 유효한 결론을 드리는 것은 아니라는 점을 감안하고 읽어주시면 좋겠습니다.</p>
<p>그리고 다시 한번 말씀드립니다. 필자는 그록봇을 결제하지도 실행해 보지도 않았고, 이 글의 요금 정보는 공개 원문과 검색 결과를 인용한 것입니다. 프로모션 금액은 계정과 지역과 시점에 따라 달라지므로, 결제하시기 전에 반드시 공식 결제 화면에서 표시되는 금액을 다시 확인하신 다음에 진행하시기 바랍니다. 이 글은 어느 경로가 있는지를 알려드리는 지도이지 결제 버튼을 대신 눌러드리는 글이 아닙니다.</p>
<p>참고한 원문은 아래에서 확인하실 수 있습니다.</p>
<ul>
<li><a href="https://news.hada.io/topic?id=32432" target="_blank" rel="noopener">Grok Bot 공개 소식 원문</a></li>
<li><a href="https://news.hada.io/topic?id=33105" target="_blank" rel="noopener">Grok Bot으로 엔지니어링 조직을 운영한 사례</a></li>
<li><a href="https://news.hada.io/topic?id=32463" target="_blank" rel="noopener">Grok 4.6 벤치마크 관련 소식</a></li>
</ul>
<p>읽어주셔서 감사합니다. 다음 글에서 뵙겠습니다.</p>
<p>The post <a rel="nofollow" href="https://blog.wonizz.com/2026/09/03/grok-bot-price-paths/">[AI Now] 그록봇 가격, 300달러 말고 3가지</a> appeared first on <a rel="nofollow" href="https://blog.wonizz.com">WONIZZ.LOG</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.wonizz.com/2026/09/03/grok-bot-price-paths/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3480</post-id>	</item>
		<item>
		<title>[AI Now] Claude Code 프롬프트 인젝션 막는 4가지</title>
		<link>https://blog.wonizz.com/2026/09/02/claude-code-prompt-injection/</link>
					<comments>https://blog.wonizz.com/2026/09/02/claude-code-prompt-injection/#respond</comments>
		
		<dc:creator><![CDATA[워니즈]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 13:08:37 +0000</pubDate>
				<category><![CDATA[AI Now]]></category>
		<category><![CDATA[AI 에이전트]]></category>
		<category><![CDATA[Claude Code]]></category>
		<category><![CDATA[보안]]></category>
		<category><![CDATA[파이썬]]></category>
		<category><![CDATA[프롬프트 인젝션]]></category>
		<guid isPermaLink="false">https://blog.wonizz.com/2026/09/02/claude-code-prompt-injection/</guid>

					<description><![CDATA[<p>The standard Lorem Ipsum passage, used since the 1500s<br />
"Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum."</p>
<p>Section 1.10.32 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"Sed ut perspiciatis unde omnis iste natus error sit voluptatem accusantium doloremque laudantium, totam rem aperiam, eaque ipsa quae ab illo inventore veritatis et quasi architecto beatae vitae dicta sunt explicabo. Nemo enim ipsam voluptatem quia voluptas sit aspernatur aut odit aut fugit, sed quia consequuntur magni dolores eos qui ratione voluptatem sequi nesciunt. Neque porro quisquam est, qui dolorem ipsum quia dolor sit amet, consectetur, adipisci velit, sed quia non numquam eius modi tempora incidunt ut labore et dolore magnam aliquam quaerat voluptatem. Ut enim ad minima veniam, quis nostrum exercitationem ullam corporis suscipit laboriosam, nisi ut aliquid ex ea commodi consequatur? Quis autem vel eum iure reprehenderit qui in ea voluptate velit esse quam nihil molestiae consequatur, vel illum qui dolorem eum fugiat quo voluptas nulla pariatur?"</p>
<p>1914 translation by H. Rackham<br />
"But I must explain to you how all this mistaken idea of denouncing pleasure and praising pain was born and I will give you a complete account of the system, and expound the actual teachings of the great explorer of the truth, the master-builder of human happiness. No one rejects, dislikes, or avoids pleasure itself, because it is pleasure, but because those who do not know how to pursue pleasure rationally encounter consequences that are extremely painful. Nor again is there anyone who loves or pursues or desires to obtain pain of itself, because it is pain, but because occasionally circumstances occur in which toil and pain can procure him some great pleasure. To take a trivial example, which of us ever undertakes laborious physical exercise, except to obtain some advantage from it? But who has any right to find fault with a man who chooses to enjoy a pleasure that has no annoying consequences, or one who avoids a pain that produces no resultant pleasure?"</p>
<p>Section 1.10.33 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"At vero eos et accusamus et iusto odio dignissimos ducimus qui blanditiis praesentium voluptatum deleniti atque corrupti quos dolores et quas molestias excepturi sint occaecati cupiditate non provident, similique sunt in culpa qui officia deserunt mollitia animi, id est laborum et dolorum fuga. Et harum quidem rerum facilis est et expedita distinctio. Nam libero tempore, cum soluta nobis est eligendi optio cumque nihil impedit quo minus id quod maxime placeat facere possimus, omnis voluptas assumenda est, omnis dolor repellendus. Temporibus autem quibusdam et aut officiis debitis aut rerum necessitatibus saepe eveniet ut et voluptates repudiandae sint et molestiae non recusandae. Itaque earum rerum hic tenetur a sapiente delectus, ut aut reiciendis voluptatibus maiores alias consequatur aut perferendis doloribus asperiores repellat."</p>
<p>1914 translation by H. Rackham<br />
"On the other hand, we denounce with righteous indignation and dislike men who are so beguiled and demoralized by the charms of pleasure of the moment, so blinded by desire, that they cannot foresee the pain and trouble that are bound to ensue; and equal blame belongs to those who fail in their duty through weakness of will, which is the same as saying through shrinking from toil and pain. These cases are perfectly simple and easy to distinguish. In a free hour, when our power of choice is untrammelled and when nothing prevents our being able to do what we like best, every pleasure is to be welcomed and every pain avoided. But in certain circumstances and owing to the claims of duty or the obligations of business it will frequently occur that pleasures have to be repudiated and annoyances accepted. The wise man therefore always holds in these matters to this principle of selection: he rejects pleasures to secure other greater pleasures, or else he endures pains to avoid worse pains."</p>
<p>Claude Code Auto Mode 를 노린 프롬프트 인젝션 사례를 정리하고, 파이썬 모듈 섀도잉을 직접 재현해본 결과와 지금 내 환경에서 확인할 수 있는 격리 항목 4가지를 적었습니다.</p>
<p>The post <a rel="nofollow" href="https://blog.wonizz.com/2026/09/02/claude-code-prompt-injection/">[AI Now] Claude Code 프롬프트 인젝션 막는 4가지</a> appeared first on <a rel="nofollow" href="https://blog.wonizz.com">WONIZZ.LOG</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The standard Lorem Ipsum passage, used since the 1500s<br />
"Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum."</p>
<p>Section 1.10.32 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"Sed ut perspiciatis unde omnis iste natus error sit voluptatem accusantium doloremque laudantium, totam rem aperiam, eaque ipsa quae ab illo inventore veritatis et quasi architecto beatae vitae dicta sunt explicabo. Nemo enim ipsam voluptatem quia voluptas sit aspernatur aut odit aut fugit, sed quia consequuntur magni dolores eos qui ratione voluptatem sequi nesciunt. Neque porro quisquam est, qui dolorem ipsum quia dolor sit amet, consectetur, adipisci velit, sed quia non numquam eius modi tempora incidunt ut labore et dolore magnam aliquam quaerat voluptatem. Ut enim ad minima veniam, quis nostrum exercitationem ullam corporis suscipit laboriosam, nisi ut aliquid ex ea commodi consequatur? Quis autem vel eum iure reprehenderit qui in ea voluptate velit esse quam nihil molestiae consequatur, vel illum qui dolorem eum fugiat quo voluptas nulla pariatur?"</p>
<p>1914 translation by H. Rackham<br />
"But I must explain to you how all this mistaken idea of denouncing pleasure and praising pain was born and I will give you a complete account of the system, and expound the actual teachings of the great explorer of the truth, the master-builder of human happiness. No one rejects, dislikes, or avoids pleasure itself, because it is pleasure, but because those who do not know how to pursue pleasure rationally encounter consequences that are extremely painful. Nor again is there anyone who loves or pursues or desires to obtain pain of itself, because it is pain, but because occasionally circumstances occur in which toil and pain can procure him some great pleasure. To take a trivial example, which of us ever undertakes laborious physical exercise, except to obtain some advantage from it? But who has any right to find fault with a man who chooses to enjoy a pleasure that has no annoying consequences, or one who avoids a pain that produces no resultant pleasure?"</p>
<p>Section 1.10.33 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"At vero eos et accusamus et iusto odio dignissimos ducimus qui blanditiis praesentium voluptatum deleniti atque corrupti quos dolores et quas molestias excepturi sint occaecati cupiditate non provident, similique sunt in culpa qui officia deserunt mollitia animi, id est laborum et dolorum fuga. Et harum quidem rerum facilis est et expedita distinctio. Nam libero tempore, cum soluta nobis est eligendi optio cumque nihil impedit quo minus id quod maxime placeat facere possimus, omnis voluptas assumenda est, omnis dolor repellendus. Temporibus autem quibusdam et aut officiis debitis aut rerum necessitatibus saepe eveniet ut et voluptates repudiandae sint et molestiae non recusandae. Itaque earum rerum hic tenetur a sapiente delectus, ut aut reiciendis voluptatibus maiores alias consequatur aut perferendis doloribus asperiores repellat."</p>
<p>1914 translation by H. Rackham<br />
"On the other hand, we denounce with righteous indignation and dislike men who are so beguiled and demoralized by the charms of pleasure of the moment, so blinded by desire, that they cannot foresee the pain and trouble that are bound to ensue; and equal blame belongs to those who fail in their duty through weakness of will, which is the same as saying through shrinking from toil and pain. These cases are perfectly simple and easy to distinguish. In a free hour, when our power of choice is untrammelled and when nothing prevents our being able to do what we like best, every pleasure is to be welcomed and every pain avoided. But in certain circumstances and owing to the claims of duty or the obligations of business it will frequently occur that pleasures have to be repudiated and annoyances accepted. The wise man therefore always holds in these matters to this principle of selection: he rejects pleasures to secure other greater pleasures, or else he endures pains to avoid worse pains."</p>
안녕하세요? 정리하는 개발자 워니즈입니다.

Claude Code 에게 &#8220;이 웹사이트 좀 요약해줘&#8221;라고 한 문장을 던졌을 때, 그 요약 요청이 내 컴퓨터에서 코드를 실행하는 경로로 이어질 수 있다는 이야기를 들으면 어떤 생각이 드시나요?

이 글은 보안 연구자가 공개한 Claude Code Auto Mode 프롬프트 인젝션 사례를 단계별로 따라 읽고, 그 공격의 핵심 부품인 파이썬 모듈 섀도잉을 필자가 직접 재현해본 뒤에 지금 내 환경에서 무엇을 확인하면 되는지를 4가지로 정리한 글입니다. 재현은 악성 페이로드 없이 표준 라이브러리를 가리는 부분만 떼어서 했고, 어디까지가 필자가 직접 본 것이고 어디부터가 원문 인용인지를 본문에 구분해두었습니다.

<strong>【한 줄 요약】</strong> 이 프롬프트 인젝션의 무서운 지점은 방어가 뚫린 것이 아니라 <strong>방어가 작동했는데도 우회 경로가 생겼다</strong>는 것입니다. 아카이브에 들어 있던 바이너리 실행은 거부됐는데 모델이 같은 일을 하는 파이썬 코드를 직접 써서 실행했고, 그 실행 디렉터리에 놓인 악성 <code>struct.py</code> 가 표준 라이브러리를 가로챘습니다. 필자가 재현해보니 <strong>디코딩 결과는 정상으로 나와서 사람이 알아챌 단서가 없었고</strong>, <code>python3 -I</code> 격리 모드로 바꾸는 것만으로 섀도잉은 멈췄습니다. Anthropic 이 이 보고를 설계 의도와 일치한다며 정보성으로 종결했으니, 패치를 기다리는 대신 실행 환경 격리와 네트워크 송신 제한과 자격 증명 분리와 격리 모드 강제를 사용자 쪽에서 걸어두는 것이 지금 할 수 있는 일입니다.

<ul>
  <li><strong>거부는 차단이 아니었다</strong>: 바이너리 실행 거부 뒤에 모델이 스스로 대체 경로를 만들었다</li>
  <li><strong>정상 동작이 은폐 수단이었다</strong>: 가로챈 모듈이 원래 API 를 그대로 재내보내 결과가 깨지지 않았다</li>
  <li><strong>막는 지점은 승인 화면이 아니다</strong>: 승인 여부가 아니라 그 프로세스가 무엇에 닿을 수 있는지가 경계다</li>
</ul>

<strong>목차</strong>

<ol>
  <li>Claude Code 프롬프트 인젝션은 정확히 무엇을 노리나요?</li>
  <li>Auto Mode 가 기본값이 되면서 달라진 것</li>
  <li>어떻게 뚫리나, 요약 요청 한 줄에서 시작한 경로</li>
  <li>거부가 곧 익스플로잇이 됐다는 말의 뜻</li>
  <li>직접 확인 1: 파이썬은 현재 디렉터리를 표준 라이브러리보다 먼저 봅니다</li>
  <li>직접 확인 2: 결과가 정상으로 나와서 알아챌 단서가 없었습니다</li>
  <li>직접 확인 3: 격리 모드로 바꾸니 섀도잉이 멈췄습니다</li>
  <li>막는 방법 4가지와 각각 무엇을 확인하면 되는지</li>
  <li>이 4가지로도 막지 못하는 것은 무엇인가요?</li>
  <li>누구에게 필요하고 누구에게는 굳이인가
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/09/pi-01-chain.png?w=1200&#038;ssl=1" alt="Claude Code 프롬프트 인젝션 공격 체인 6단계 흐름도" />
  </li>
</ol>

<hr />

<h2>1. Claude Code 프롬프트 인젝션은 정확히 무엇을 노리나요?</h2>

노리는 것은 모델의 판단이 아니라 <strong>모델이 이미 갖고 있는 실행 권한</strong>입니다. 프롬프트 인젝션이라고 하면 보통 대화창에 이상한 문장을 넣어 답을 비틀어놓는 장난 정도로 떠올리시는 경우가 많은데요, 코딩 에이전트는 파일을 읽고 쓰고 명령을 실행하는 권한을 이미 손에 쥔 상태라서 지시를 한 줄 심는 데 성공하면 그 지시가 곧바로 내 컴퓨터에서 도는 명령이 됩니다.

여기서 간접이라는 말이 붙는 이유는 공격자가 내 대화창에 직접 타이핑하는 것이 아니라 <strong>내가 읽어오라고 시킨 외부 자료 안에 지시를 숨겨두는 방식</strong>이기 때문인데요, 웹페이지 본문이든 저장소의 README 든 압축 파일 안의 텍스트든 모델이 읽는 모든 것이 후보가 됩니다. 사용자는 요약해달라는 지극히 평범한 문장 하나만 입력했고, 나머지는 읽어온 자료가 시킨 대로 흘러갑니다.

이번 프롬프트 인젝션 사례를 찾아낸 사람은 보안 연구자 Johann Rehberger 이고 온라인에서는 wunderwuzzi 라는 이름으로 활동하는데요, 자신의 블로그 Embrace The Red 에 <a href="https://embracethered.com/blog/posts/2026/breaking-claude-code-opus-5-and-automode/" target="_blank" rel="noopener">Claude Code 와 Auto Mode 를 대상으로 한 분석 글</a>을 공개했고 한국어로는 <a href="https://news.hada.io/topic?id=33079" target="_blank" rel="noopener">GeekNews 요약</a>으로도 올라와 있습니다.

<h3>이건 특정 버전의 버그라서 곧 고쳐지는 건가요?</h3>

그렇게 보기 어렵습니다. 연구자가 이 내용을 Anthropic 에 보고했는데 1차로 모델 버그바운티 주소로 보낸 것은 답이 없었고, 공식 보안 채널로 다시 보내 빠른 회신을 받았지만 그 내용이 <strong>정보성으로 종결이며 설계 의도와 일치한다</strong>는 것이었습니다.

버그로 접수되어 다음 릴리스에서 막히는 종류가 아니라는 뜻이고, 다시 말해 <strong>에이전트에게 실행 권한을 준 쪽이 그 실행이 무엇에 닿을 수 있는지를 스스로 좁혀두는 것</strong>이 전제로 깔린 도구라는 뜻입니다. 그래서 이 글의 후반부는 취약점 해설이 아니라 내 환경을 어떻게 좁힐지에 대한 이야기가 됩니다.

<hr />

<h2>2. Auto Mode 가 기본값이 되면서 달라진 것</h2>

Auto Mode 는 2026년 8월 8일부터 Pro 와 Max 와 Team 플랜에서 기본값이 됐습니다. 이 변화가 이번 프롬프트 인젝션에서 중요한 이유는 원래 사람이 눈으로 보고 승인하던 자리를 판단 주체가 대신 채우게 됐기 때문인데요, 승인 절차가 있을 때 사람이 하던 일은 이 명령이 내가 시킨 일과 맞는지를 보는 것과 명령 문자열 자체가 수상한지를 보는 것 두 가지였습니다.

그런데 이번 공격 체인에서 실제로 흘러간 명령들은 <strong>둘 다 통과하기에 충분히 평범했습니다.</strong> 압축 파일을 풀고 인코딩된 데이터를 디코딩하는 파이썬 한 줄은 개발자가 하루에도 몇 번씩 치는 종류라서 문자열만 보고 걸러내기가 애초에 어렵습니다. 원문이 대응 항목 중에 <strong>Auto Mode 의 승인을 보안 보장으로 간주하지 말라</strong>는 문장을 넣어둔 것도 그 자리인데요, 승인은 이 명령이 지금 흐름에서 말이 된다는 판단일 뿐이고 안전하다는 증명은 아닙니다.

<blockquote>Auto Mode 가 승인했다는 사실은 명령이 안전하다는 증거가 아닙니다.</p></blockquote>

<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/09/pi-02-approval.png?w=1200&#038;ssl=1" alt="프롬프트 인젝션 상황에서 사람 승인과 자동 승인의 차이" />

필자도 이 대목에서 뜨끔한 경험이 하나 있습니다. 개인 블로그를 자동으로 운영하면서 발행 전에 원고를 점검하는 검사기를 만들어 쓰고 있는데요, 어느 날 그 검사기가 통과를 내줬는데 실제로는 해당 항목을 아예 검사하지 않고 있던 일이 있었습니다. 통과라는 표시가 검사했다는 뜻이 아니었던 셈이니, 자동 승인을 안전의 근거로 읽으면 안 된다는 이 글의 논지와 정확히 같은 계열의 실수였습니다.

<hr />

<h2>3. 어떻게 뚫리나, 요약 요청 한 줄에서 시작한 경로</h2>

원문에 적힌 프롬프트 인젝션 체인을 순서대로 옮기면 아래와 같은데, 각 단계가 따로 보면 전부 있을 수 있는 일이라는 점을 보면서 읽으시면 좋겠습니다.

<figure class="wp-block-table">

<table><thead><tr><th>단계</th><th>무슨 일이 일어났나</th></tr></thead><tbody><tr><td>1</td><td>사용자가 웹사이트를 요약해달라고 요청했다</td></tr><tr><td>2</td><td>악성 사이트가 WebFetch 요청에 HTTP 415 Unsupported Media Type 을 반환해 다른 경로를 택하게 유도했다</td></tr><tr><td>3</td><td>자료 보관소로 위장한 ZIP 을 처리하는 흐름으로 넘어갔다</td></tr><tr><td>4</td><td>아카이브에 든 <code>decoder-darwin</code> 바이너리 실행은 거부됐다</td></tr><tr><td>5</td><td>모델이 대신 자체 파이썬 디코더를 작성해 압축 해제 디렉터리 안에서 실행했다</td></tr><tr><td>6</td><td>그 디렉터리의 악성 <code>struct.py</code> 가 표준 라이브러리를 가리고 import 중에 코드를 실행했다</td></tr><tr><td>7</td><td>격리된 파이썬 자식 프로세스가 원격 스테이지를 받아 실행했다</td></tr></tbody></table>

</figure>

2단계의 415 응답이 특히 인상적인 부분입니다. 에러를 내서 막는 것이 아니라 <strong>에러를 내서 다른 길로 유도한다</strong>는 발상인데요, 정상적인 도구 호출이 실패하면 다른 방법을 찾아보는 것은 에이전트가 마땅히 해야 하는 일이고 사용자도 그걸 기대하는데 그 성실함이 그대로 입력으로 쓰였습니다.

6단계에서 나오는 섀도잉이 이 체인의 심장입니다. 파이썬은 모듈을 import 할 때 정해진 순서로 경로를 훑는데 <code>python3 -c</code> 로 실행하면 그 목록의 맨 앞이 현재 디렉터리가 되기 때문에, <strong>현재 디렉터리에 <code>struct.py</code> 라는 파일이 있으면 표준 라이브러리의 struct 대신 그 파일이 로드됩니다.</strong> 여기서 악성 모듈은 원래 struct 가 하던 일을 막는 대신 실제 <code>_struct</code> API 를 그대로 다시 내보내 정상 동작을 유지했고, 그와 함께 난독화해둔 모듈 레벨 표현식을 import 되는 순간에 실행시켰습니다.

7단계의 자식 프로세스는 <code>python3 -I -c</code> 라는 격리 모드로 떠서 같은 섀도잉에 재귀적으로 걸리지 않게 했는데요, 뒤에서 볼 방어 항목 중 하나가 바로 이 옵션이라는 점이 좀 묘합니다. 원문 기준으로 실험실 환경에서 이 페이로드는 C2 서버로 콜백을 보내고 계산기를 띄웠으며, <strong>분리된 자식 프로세스는 Claude Code 세션이 끝난 뒤에도 살아남을 수 있었습니다.</strong>

<figure class="wp-block-table">

<table><thead><tr><th>경로</th><th>성공률 (소규모 표본)</th></tr></thead><tbody><tr><td>C2 체인</td><td>5회 중 3회, 60%</td></tr><tr><td><code>claude -p</code> 자식 프로세스</td><td>5회 중 4회, 80%</td></tr></tbody></table>

</figure>

환경은 Opus 5 에 Auto Mode 였습니다. 표본이 각각 5회라 이 숫자를 확률로 받아들이기는 어렵고, <strong>매번 성공하지는 않지만 여러 번 시도하면 통과한다</strong> 정도로 읽는 것이 맞을 것 같습니다.

<hr />

<h2>4. 거부가 곧 익스플로잇이 됐다는 말의 뜻</h2>

앞의 표에서 4단계와 5단계를 붙여서 다시 읽어보시면 이 프롬프트 인젝션의 성격이 드러납니다. 아카이브에 들어 있던 알 수 없는 바이너리를 실행하려는 시도는 <strong>거부됐습니다.</strong> 방어가 제대로 작동한 것이고 여기서 흐름이 끝났다면 이 글은 쓰일 일이 없었는데, 그다음에 일어난 일이 모델이 그럼 직접 짜서 하겠다는 쪽으로 돌아선 것입니다.

요청받은 목적은 자료를 디코딩하는 것이었으니 바이너리가 막혔으면 같은 일을 하는 코드를 쓰는 것이 합리적인 다음 수이고 그 판단 자체는 나무랄 데가 없는데요, 문제는 그렇게 작성된 코드가 <strong>압축을 풀어둔 그 디렉터리 안에서 실행됐다</strong>는 것이고 공격자가 노린 지점이 정확히 거기였습니다.
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/09/pi-03-refusal-bypass.png?w=1200&#038;ssl=1" alt="바이너리 실행 거부가 프롬프트 인젝션 우회 경로를 만든 순서" />
이 구조를 한 문장으로 줄이면 <strong>거부라는 방어가 우회를 만들어내는 입력이 됐다</strong>는 것입니다. 보안에서 흔히 쓰는 전제 하나가 여기서 깨지는데요, 우리는 보통 방어를 세우면 최악의 경우에도 아무 일이 일어나지 않는다고 생각하지만 목적을 달성하려는 판단 주체가 중간에 있으면 막힌 자리에서 멈추는 대신 다른 길을 찾습니다.

그래서 이 사례에서 배울 것은 금지 목록에 무엇을 더 넣을지가 아닙니다. 실행을 막는 항목을 하나 더 추가해도 그 옆으로 도는 길이 또 만들어질 수 있고 이번에는 바이너리 실행 금지라는 항목이 있었는데도 그렇게 됐으니, <strong>막을 지점을 명령의 종류가 아니라 그 명령이 닿을 수 있는 범위로 옮겨야 한다</strong>는 것이 이 글에서 4가지를 고른 기준입니다.

<hr />

<h2>5. 직접 확인 1: 파이썬은 현재 디렉터리를 표준 라이브러리보다 먼저 봅니다</h2>

여기서부터는 필자가 2026년 9월 2일에 직접 돌려본 결과입니다. 환경은 macOS 이고 파이썬은 3.14.4 인데요, 악성 페이로드는 쓰지 않고 <strong>표준 라이브러리를 가리는 부분만 떼어서</strong> 확인했습니다. 먼저 확인할 것은 모듈을 찾는 경로의 맨 앞에 무엇이 있는지입니다.

<pre class="wp-block-code"><code>python3 -c "import sys; print(repr(sys.path[0]))"</code></pre>

결과는 빈 문자열이었습니다. 따옴표 두 개만 찍혀 나오는데요, 파이썬에서 이 빈 문자열은 아무것도 없다는 뜻이 아니라 <strong>현재 디렉터리</strong>를 가리키고 이 항목이 표준 라이브러리 경로보다 먼저 검사됩니다.

<figure class="wp-block-table">

<table><thead><tr><th>검사 순서</th><th>무엇을 보나</th><th>이번 사례에서의 의미</th></tr></thead><tbody><tr><td>1</td><td>현재 디렉터리, 빈 문자열로 표시된다</td><td>압축을 풀어둔 그 디렉터리가 여기에 해당한다</td></tr><tr><td>2</td><td><code>PYTHONPATH</code> 환경 변수</td><td>이번 체인에서는 쓰이지 않았다</td></tr><tr><td>3</td><td>표준 라이브러리</td><td>원래 로드되어야 할 <code>struct</code> 가 여기에 있다</td></tr><tr><td>4</td><td>설치된 패키지</td><td>이번 사례와 무관하다</td></tr></tbody></table>

</figure>

이 한 줄짜리 확인이 왜 중요한지는 3절 프롬프트 인젝션 체인의 5단계와 겹쳐놓으면 분명해집니다. 모델이 작성한 디코더는 압축을 풀어둔 디렉터리 안에서 실행됐고 그 디렉터리가 검사 순서 1번이니, <strong>그 안에 표준 라이브러리와 같은 이름의 파일을 두는 것만으로 로드 대상이 바뀝니다.</strong> 별다른 권한도 설정 변경도 필요하지 않고 파일 하나를 같이 넣어두면 끝인데요, 이건 파이썬의 결함이 아니라 문서에 적혀 있는 동작이라 고쳐질 성질의 것도 아닙니다.

<hr />

<h2>6. 직접 확인 2: 결과가 정상으로 나와서 알아챌 단서가 없었습니다</h2>

이번에는 임시 디렉터리를 하나 만들고 그 안에 <code>struct.py</code> 를 두었습니다. 내용은 표준 라이브러리의 실제 구현인 <code>_struct</code> 를 그대로 다시 내보내면서 표시 문구 한 줄을 출력하는 세 줄이었습니다.

<pre class="wp-block-code"><code class="language-python">import _struct
from _struct import *
print("[표시] 현재 디렉터리의 struct.py 가 로드됐습니다")</code></pre>

그 디렉터리에서 struct 를 import 하고 정수 하나를 언팩해봤습니다.

&lt;

pre class=&#8221;wp-block-code&#8221;><code class="language-bash">python3 -c "import struct; print(struct.<strong>file</strong>)
print(struct.unpack('&lt;i', b'\x01\x00\x00\x00'))"</code></pre>
먼저 표시 문구가 출력되고 <code>struct.__file__</code> 이 <strong>표준 라이브러리가 아니라 그 임시 디렉터리의 struct.py</strong> 를 가리켰는데 여기까지는 예상한 대로입니다. 그런데 두 번째 줄에서 <code>unpack</code> 결과가 <code>(1,)</code> 로 <strong>정상</strong>이었고, 가로챈 모듈이 원래 함수들을 그대로 재내보냈기 때문에 겉으로 보이는 동작에는 아무 변화가 없었습니다. <strong>결과가 깨지면 사람이 알아채는데 안 깨지므로 알아챌 단서가 없습니다.</strong>
<figure class="wp-block-table">

<table><thead><tr><th>관찰 항목</th><th>섀도잉 상태에서 본 값</th><th>사람이 이상을 느끼나</th></tr></thead><tbody><tr><td>디코딩 결과</td><td><code>(1,)</code> 로 정상</td><td>느끼지 못한다</td></tr><tr><td>에러나 경고</td><td>없음</td><td>느끼지 못한다</td></tr><tr><td>소요 시간</td><td>재보지 않았다</td><td>판단 근거가 없다</td></tr><tr><td><code>struct.__file__</code></td><td>임시 디렉터리 경로</td><td>일부러 찍어봐야 보인다</td></tr></tbody></table>

</figure>
표의 마지막 줄만이 유일한 신호인데 이걸 평소에 찍어보는 사람은 거의 없습니다. 필자도 이번에 재현하려고 일부러 찍어본 것이고, 실제 작업 중이었다면 디코딩이 잘 됐다는 결과만 보고 다음 단계로 넘어갔을 것 같습니다.
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/09/pi-04-three-checks.png?w=1200&#038;ssl=1" alt="파이썬 모듈 섀도잉을 직접 확인한 세 가지 결과" />

<h3>결과가 정상인데 왜 이게 더 나쁜 건가요?</h3>

탐지의 근거가 사라지기 때문입니다. 우리가 무언가 잘못됐다는 것을 알아채는 통로는 대부분 결과물인데요, 파일이 깨지거나 에러가 뜨거나 값이 이상하게 나오면 그 자리에서 손을 멈추고 들여다보게 되는데 이 프롬프트 인젝션은 그 통로를 아예 쓰지 않습니다. 그래서 어떤 신호를 놓쳤느냐가 아니라 <strong>처음부터 신호가 없었다</strong>고 보는 것이 맞고, 사람이 더 주의를 기울이는 방식으로는 개선되지 않는 종류라는 뜻이기도 합니다.

<hr />

<h2>7. 직접 확인 3: 격리 모드로 바꾸니 섀도잉이 멈췄습니다</h2>

같은 디렉터리에서 옵션 하나만 바꿔서 다시 돌려봤습니다. 파일도 그대로 두고 명령도 그대로 두고 <code>-I</code> 만 붙였습니다.

<pre class="wp-block-code"><code>python3 -I -c "import struct; print(struct.__file__)"</code></pre>

이번에는 표시 문구가 나오지 않고 <code>struct.__file__</code> 이 <strong>표준 라이브러리 경로</strong>를 가리켰습니다. 즉 격리 모드가 현재 디렉터리를 모듈 검색 경로에서 빼면서 섀도잉을 실제로 막았는데, 옵션 두 글자를 붙인 것이 전부인데도 결과는 정반대로 갈렸습니다. <code>-I</code> 는 현재 디렉터리와 환경 변수와 사용자별 설치 경로를 한꺼번에 무시하는 옵션이라 딱 이 프롬프트 인젝션이 쓰는 통로를 닫는데요, 3절에서 공격 쪽 자식 프로세스가 이 옵션을 쓴 것도 같은 이유였으니 <strong>공격자가 자기 방어에 쓴 옵션이 곧 방어 항목이 되는 셈</strong>입니다.
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/09/pi-05-isolated-mode.png?w=1200&#038;ssl=1" alt="python3 격리 모드가 모듈 섀도잉을 막은 결과 비교" />

<h3>확인하지 못한 것</h3>

필자가 재현한 것은 <strong>모듈 섀도잉이 성립하는지와 격리 모드가 그것을 막는지까지</strong>이고, 실제 악성 페이로드는 재현하지 않았습니다.

<ul>
  <li>C2 서버로의 콜백은 <strong>원문 보고를 인용한 것</strong>이고 필자가 본 결과가 아닙니다</li>
  <li>자식 프로세스가 세션 종료 후에도 살아남는다는 부분도 <strong>원문 인용</strong>이며 필자가 확인하지 못했습니다</li>
  <li>성공률 60% 와 80% 역시 원문의 소규모 표본 결과이고 필자가 다시 측정하지 않았습니다</li>
  <li>415 응답으로 경로를 유도하는 부분은 재현 대상에서 제외했습니다</li>
</ul>

<hr />

<h2>8. 막는 방법 4가지와 각각 무엇을 확인하면 되는지</h2>

원문이 제시한 프롬프트 인젝션 대응 중에서 지금 바로 손댈 수 있는 것을 4가지로 묶었고 순서는 효과가 큰 쪽부터입니다.

<strong>첫째, 격리된 실행 환경에서 돌립니다.</strong> 컨테이너나 가상 머신 또는 OS 수준 샌드박스 안에서 에이전트를 실행하는 것인데요, 앞에서 본 것처럼 명령의 종류를 하나씩 막는 방식에는 우회가 생기기 때문에 <strong>명령이 닿을 수 있는 범위 자체를 좁히는 것</strong>이 유일하게 구조적인 대응입니다. 확인할 것은 지금 에이전트가 도는 자리에서 내 홈 디렉터리가 보이는지이고, 프로젝트 폴더 하나만 마운트해두고 그 밖이 안 보이는 상태가 목표입니다.

<strong>둘째, 네트워크 송신을 제한합니다.</strong> 이번 체인의 마지막 두 단계는 전부 밖으로 나가는 연결이었는데, 들어오는 연결을 막는 것과 달리 <strong>나가는 연결을 제한하는 설정은 평소에 잘 안 걸어둡니다.</strong> 확인할 것은 에이전트가 도는 환경에서 임의의 외부 호스트로 연결이 되는지이고, 되어야 할 곳만 남기고 막아두면 페이로드가 실행되어도 다음 단계로 넘어가지 못합니다.

<strong>셋째, 자격 증명을 분리합니다.</strong> 홈 디렉터리와 SSH 키와 클라우드 자격 증명이 그 프로세스에서 읽히지 않아야 하는데요, 코드 실행 자체보다 무거운 것은 그 실행이 무엇을 집어갈 수 있는지이기 때문입니다. 확인할 것은 에이전트가 도는 자리에서 <code>~/.ssh</code> 와 클라우드 설정 폴더와 환경 변수에 든 토큰이 보이는지이고, 필자 기준으로는 평소에 편의를 위해 다 열어두는 자리라서 여기가 가장 손이 많이 갔습니다.

<strong>넷째, 격리 모드를 강제하고 압축 파일은 먼저 들여다봅니다.</strong> 7절에서 본 대로 <code>python3 -I</code> 는 이 공격이 쓰는 통로를 닫고, 압축 파일을 풀기만 하고 그 안에서 무언가 실행하기 전에 목록을 훑어보면 표준 라이브러리와 같은 이름의 파일이 섞여 있는지를 알 수 있습니다. 확인할 것은 아카이브 안에 <code>struct.py</code> 같은 표준 모듈 이름의 파일이 있는지, 그리고 압축을 푼 디렉터리를 작업 디렉터리로 삼아 스크립트를 돌리고 있지 않은지입니다.
<figure class="wp-block-table">

<table><thead><tr><th>막는 방법</th><th>무엇을 확인하나</th><th>이번 체인에서 끊기는 지점</th></tr></thead><tbody><tr><td>격리된 실행 환경</td><td>홈 디렉터리와 그 밖이 보이는지</td><td>5단계 이후 전부</td></tr><tr><td>네트워크 송신 제한</td><td>임의 외부 호스트로 나가는 연결이 되는지</td><td>7단계</td></tr><tr><td>자격 증명 분리</td><td>SSH 키와 클라우드 키와 토큰이 읽히는지</td><td>유출 범위</td></tr><tr><td>격리 모드와 압축 선검사</td><td><code>-I</code> 를 쓰는지, 아카이브에 표준 모듈 이름이 있는지</td><td>6단계</td></tr></tbody></table>

</figure>
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/09/pi-06-verdict.png?w=1200&#038;ssl=1" alt="프롬프트 인젝션 보고에 대한 Anthropic 판정 요약" />
표에서 눈에 걸리는 것은 네 항목 중 세 항목이 <strong>실행을 막는 것이 아니라 실행 이후를 좁히는 것</strong>이라는 점입니다. 실행 자체를 목록으로 막는 방식에는 우회가 만들어지니, 실행이 일어난다는 것을 전제로 두고 그때 무엇에 닿을 수 있는지를 줄이는 편이 낫습니다. 여기에 하나 더 얹자면 무엇을 설치해 쓰는지도 같은 층위의 문제인데요, 에이전트에 붙이는 확장을 고를 때 훅과 외부 호출과 텔레메트리를 확인하는 절차는 필자가 <a href="https://blog.wonizz.com/2026/08/31/claude-code-plugin-checklist/">Claude Code 플러그인 설치 전 확인 3가지</a>에 정리해두었습니다.

<hr />

<h2>9. 이 4가지로도 막지 못하는 것은 무엇인가요?</h2>

막지 못하는 것이 꽤 있습니다. 먼저 <strong>읽어온 내용이 판단을 비트는 것 자체는 못 막습니다.</strong> 4가지는 전부 실행 이후를 좁히는 장치라서 모델이 외부 자료에 심긴 지시를 그럴듯한 다음 수로 받아들이는 것은 그대로 남는데요, 격리된 환경 안에서라면 피해 범위가 그 안으로 묶이지만 그 안에서 벌어지는 일은 여전히 벌어집니다.

다음으로 <strong>격리 환경 안의 자료는 지켜지지 않습니다.</strong> 컨테이너에 프로젝트 폴더를 마운트해뒀다면 그 폴더는 읽히고 쓰일 수 있고, 여기서 흔한 사고 하나가 소스 트리에 들어 있는 설정 파일에 자격 증명이 적혀 있는 경우인데요, 홈 디렉터리를 잘 막아두고도 프로젝트 안의 파일로 새어나가는 것이라 격리 문제가 아니라 그 자료를 어디에 두었는지의 문제입니다.

세 번째로 <strong>나가는 연결을 완전히 끊기는 어렵습니다.</strong> 패키지를 받아오고 문서를 조회하는 것이 에이전트가 하는 일의 상당 부분이라 실무에서는 필요한 곳을 열어두게 되는데요, 열어둔 목적지가 임의의 내용을 실어 보낼 수 있는 곳이라면 그 경로로 나갈 수 있습니다. 네 번째로 <strong>세션을 닫는 것이 정리가 아닙니다.</strong> 원문 보고에 따르면 분리된 자식 프로세스는 세션이 끝난 뒤에도 살아남을 수 있었는데, 필자가 재현하지 못한 부분이지만 사실이라면 창을 닫아서 상황이 종료됐다고 보는 습관 자체가 어긋난다는 뜻입니다.
<figure class="wp-block-table">

<table><thead><tr><th>못 막는 것</th><th>남는 위험</th><th>그래서 대신 무엇을 하나</th></tr></thead><tbody><tr><td>판단이 비틀리는 것</td><td>격리 안에서 같은 흐름이 반복된다</td><td>피해 범위를 격리로 묶는다</td></tr><tr><td>격리 안의 자료</td><td>프로젝트 파일의 자격 증명이 노출된다</td><td>자격 증명을 소스 트리 밖에 둔다</td></tr><tr><td>나가는 연결 전면 차단</td><td>열어둔 목적지로 나갈 수 있다</td><td>목적지를 최소한으로 줄인다</td></tr><tr><td>세션 종료로 정리</td><td>자식 프로세스가 남을 수 있다</td><td>프로세스가 남았는지 따로 본다</td></tr></tbody></table>

</figure>
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/09/pi-07-blast-radius.png?w=1200&#038;ssl=1" alt="프롬프트 인젝션 대응 4가지를 걸었을 때 달라지는 도달 범위" />
필자가 이 절을 굳이 넣은 이유는 4가지를 다 걸었으니 프롬프트 인젝션은 끝났다고 읽히는 것이 가장 위험하기 때문인데요, <strong>이 항목들이 하는 일은 위험을 없애는 것이 아니라 도달 범위를 줄이는 것</strong>이고 그 차이를 알고 쓰는 것과 모르고 쓰는 것은 다음에 새로운 우회가 나왔을 때 반응이 갈립니다.

<hr />

<h2>10. 누구에게 필요하고 누구에게는 굳이인가</h2>

정리하면 이번 Claude Code 프롬프트 인젝션 사례에서 진짜 배울 것은 특정 취약점의 생김새가 아니라 <strong>거부라는 방어가 우회를 만드는 입력이 될 수 있다</strong>는 구조이고, 필자가 직접 재현해본 결과 그 우회의 부품인 모듈 섀도잉은 결과를 깨뜨리지 않아서 사람이 알아챌 단서를 남기지 않았습니다. 대응은 사용자 쪽에 있고, 실행 환경 격리와 네트워크 송신 제한과 자격 증명 분리와 격리 모드 강제 4가지가 지금 확인할 수 있는 항목입니다.

<strong>점검이 필요한 분</strong>은 코딩 에이전트에 파일과 명령 실행 권한을 주고 자기 컴퓨터에서 그대로 돌리시는 분이고, 특히 외부 URL 이나 저장소 내용을 읽어와 처리하는 흐름이 있으시다면 이번 체인의 1단계와 형태가 같습니다. 필자도 개인 블로그를 자동으로 운영하면서 외부 기사 URL 을 읽어 요약하는 단계를 돌리고 있는데요, <strong>읽는 대상이 필자 통제 밖이라는 점이 정확히 같아서</strong> 이번 사례를 남의 이야기로 넘기기 어려웠습니다.

<strong>굳이 안 하셔도 되는 경우</strong>는 에이전트를 대화만 하는 용도로 쓰시고 파일 쓰기나 명령 실행을 허용하지 않으시는 경우입니다. 실행 권한이 없으면 이 체인은 5단계에서 멈추는데요, 그래도 4가지 중 세 번째는 몇 분이면 확인되니 지금 그 프로세스에서 SSH 키와 클라우드 자격 증명이 읽히는지만 한 번 열어보시는 것을 권해드리고 싶습니다.

에이전트를 돌리는 비용 쪽을 함께 줄이고 싶으시다면 <a href="https://blog.wonizz.com/2026/09/01/claude-code-plugin-token/">Claude Code 플러그인 토큰 줄이기 3단계</a>에 상시로 나가는 부분을 재는 방법을 적어두었고, 격리된 환경에서 가볍게 붙여 쓸 모델을 찾으신다면 <a href="https://blog.wonizz.com/2026/08/29/glm-5-3-flash-free-usage/">GLM-5.3-Flash 무료 사용법</a>도 같이 보시면 좋겠습니다. 원문 분석의 전체 내용은 <a href="https://embracethered.com/blog/posts/2026/breaking-claude-code-opus-5-and-automode/" target="_blank" rel="noopener">Embrace The Red 의 공개 글</a>에서, 한국어 요약은 <a href="https://news.hada.io/topic?id=33079" target="_blank" rel="noopener">GeekNews</a>에서 확인하실 수 있습니다.

여기까지 읽어주셔서 감사합니다. 다음에도 직접 돌려본 것과 원문에서 인용한 것을 구분해서 적어보겠습니다.
<h2 class="wp-block-heading">함께 보면 좋은 글</h2>
<ul class="wp-block-list"><li><a href="https://blog.wonizz.com/2026/08/26/claude-agent-collaboration-review/">[서평 작성] 클로드 에이전트 협업의 기술</a></li><li><a href="https://blog.wonizz.com/2026/09/03/grok-bot-price-paths/">[AI Now] 그록봇 가격, 300달러 말고 3가지</a></li><li><a href="https://blog.wonizz.com/2026/08/28/humanizer-korean-ai-writing-check/">[AI Now] humanizer 사용법과 쉼표 73%</a></li><li><a href="https://blog.wonizz.com/2026/08/22/ai-automation-completion-condition-reality/">[AI Now] AI 자동화 성공률 29%, 실패 원인 분석</a></li></ul>
<p>The post <a rel="nofollow" href="https://blog.wonizz.com/2026/09/02/claude-code-prompt-injection/">[AI Now] Claude Code 프롬프트 인젝션 막는 4가지</a> appeared first on <a rel="nofollow" href="https://blog.wonizz.com">WONIZZ.LOG</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.wonizz.com/2026/09/02/claude-code-prompt-injection/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3456</post-id>	</item>
		<item>
		<title>[서평 작성] 클로드 에이전트 협업의 기술</title>
		<link>https://blog.wonizz.com/2026/08/26/claude-agent-collaboration-review/</link>
					<comments>https://blog.wonizz.com/2026/08/26/claude-agent-collaboration-review/#respond</comments>
		
		<dc:creator><![CDATA[워니즈]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 00:18:55 +0000</pubDate>
				<category><![CDATA[도서 리뷰]]></category>
		<category><![CDATA[AI 에이전트]]></category>
		<category><![CDATA[Claude Code]]></category>
		<category><![CDATA[MCP]]></category>
		<category><![CDATA[멀티 에이전트]]></category>
		<category><![CDATA[서평]]></category>
		<category><![CDATA[클로드]]></category>
		<guid isPermaLink="false">https://blog.wonizz.com/?p=3372</guid>

					<description><![CDATA[<p>The standard Lorem Ipsum passage, used since the 1500s<br />
"Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum."</p>
<p>Section 1.10.32 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"Sed ut perspiciatis unde omnis iste natus error sit voluptatem accusantium doloremque laudantium, totam rem aperiam, eaque ipsa quae ab illo inventore veritatis et quasi architecto beatae vitae dicta sunt explicabo. Nemo enim ipsam voluptatem quia voluptas sit aspernatur aut odit aut fugit, sed quia consequuntur magni dolores eos qui ratione voluptatem sequi nesciunt. Neque porro quisquam est, qui dolorem ipsum quia dolor sit amet, consectetur, adipisci velit, sed quia non numquam eius modi tempora incidunt ut labore et dolore magnam aliquam quaerat voluptatem. Ut enim ad minima veniam, quis nostrum exercitationem ullam corporis suscipit laboriosam, nisi ut aliquid ex ea commodi consequatur? Quis autem vel eum iure reprehenderit qui in ea voluptate velit esse quam nihil molestiae consequatur, vel illum qui dolorem eum fugiat quo voluptas nulla pariatur?"</p>
<p>1914 translation by H. Rackham<br />
"But I must explain to you how all this mistaken idea of denouncing pleasure and praising pain was born and I will give you a complete account of the system, and expound the actual teachings of the great explorer of the truth, the master-builder of human happiness. No one rejects, dislikes, or avoids pleasure itself, because it is pleasure, but because those who do not know how to pursue pleasure rationally encounter consequences that are extremely painful. Nor again is there anyone who loves or pursues or desires to obtain pain of itself, because it is pain, but because occasionally circumstances occur in which toil and pain can procure him some great pleasure. To take a trivial example, which of us ever undertakes laborious physical exercise, except to obtain some advantage from it? But who has any right to find fault with a man who chooses to enjoy a pleasure that has no annoying consequences, or one who avoids a pain that produces no resultant pleasure?"</p>
<p>Section 1.10.33 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"At vero eos et accusamus et iusto odio dignissimos ducimus qui blanditiis praesentium voluptatum deleniti atque corrupti quos dolores et quas molestias excepturi sint occaecati cupiditate non provident, similique sunt in culpa qui officia deserunt mollitia animi, id est laborum et dolorum fuga. Et harum quidem rerum facilis est et expedita distinctio. Nam libero tempore, cum soluta nobis est eligendi optio cumque nihil impedit quo minus id quod maxime placeat facere possimus, omnis voluptas assumenda est, omnis dolor repellendus. Temporibus autem quibusdam et aut officiis debitis aut rerum necessitatibus saepe eveniet ut et voluptates repudiandae sint et molestiae non recusandae. Itaque earum rerum hic tenetur a sapiente delectus, ut aut reiciendis voluptatibus maiores alias consequatur aut perferendis doloribus asperiores repellat."</p>
<p>1914 translation by H. Rackham<br />
"On the other hand, we denounce with righteous indignation and dislike men who are so beguiled and demoralized by the charms of pleasure of the moment, so blinded by desire, that they cannot foresee the pain and trouble that are bound to ensue; and equal blame belongs to those who fail in their duty through weakness of will, which is the same as saying through shrinking from toil and pain. These cases are perfectly simple and easy to distinguish. In a free hour, when our power of choice is untrammelled and when nothing prevents our being able to do what we like best, every pleasure is to be welcomed and every pain avoided. But in certain circumstances and owing to the claims of duty or the obligations of business it will frequently occur that pleasures have to be repudiated and annoyances accepted. The wise man therefore always holds in these matters to this principle of selection: he rejects pleasures to secure other greater pleasures, or else he endures pains to avoid worse pains."</p>
<p>클로드 에이전트를 팀으로 굴리는 방법을 다룬 책입니다. 클로드 코워크의 커넥터와 스킬, 클로드 코드의 CLAUDE.md와 서브 에이전트, 멀티 에이전트 설계 패턴 네 가지까지 17개 장을 정리하고, 개인 블로그를 무인으로 돌려본 필자 경험과 대조해 어디까지 실제로 쓸 수 있는지 적었습니</p>
<p>The post <a rel="nofollow" href="https://blog.wonizz.com/2026/08/26/claude-agent-collaboration-review/">[서평 작성] 클로드 에이전트 협업의 기술</a> appeared first on <a rel="nofollow" href="https://blog.wonizz.com">WONIZZ.LOG</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The standard Lorem Ipsum passage, used since the 1500s<br />
"Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum."</p>
<p>Section 1.10.32 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"Sed ut perspiciatis unde omnis iste natus error sit voluptatem accusantium doloremque laudantium, totam rem aperiam, eaque ipsa quae ab illo inventore veritatis et quasi architecto beatae vitae dicta sunt explicabo. Nemo enim ipsam voluptatem quia voluptas sit aspernatur aut odit aut fugit, sed quia consequuntur magni dolores eos qui ratione voluptatem sequi nesciunt. Neque porro quisquam est, qui dolorem ipsum quia dolor sit amet, consectetur, adipisci velit, sed quia non numquam eius modi tempora incidunt ut labore et dolore magnam aliquam quaerat voluptatem. Ut enim ad minima veniam, quis nostrum exercitationem ullam corporis suscipit laboriosam, nisi ut aliquid ex ea commodi consequatur? Quis autem vel eum iure reprehenderit qui in ea voluptate velit esse quam nihil molestiae consequatur, vel illum qui dolorem eum fugiat quo voluptas nulla pariatur?"</p>
<p>1914 translation by H. Rackham<br />
"But I must explain to you how all this mistaken idea of denouncing pleasure and praising pain was born and I will give you a complete account of the system, and expound the actual teachings of the great explorer of the truth, the master-builder of human happiness. No one rejects, dislikes, or avoids pleasure itself, because it is pleasure, but because those who do not know how to pursue pleasure rationally encounter consequences that are extremely painful. Nor again is there anyone who loves or pursues or desires to obtain pain of itself, because it is pain, but because occasionally circumstances occur in which toil and pain can procure him some great pleasure. To take a trivial example, which of us ever undertakes laborious physical exercise, except to obtain some advantage from it? But who has any right to find fault with a man who chooses to enjoy a pleasure that has no annoying consequences, or one who avoids a pain that produces no resultant pleasure?"</p>
<p>Section 1.10.33 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"At vero eos et accusamus et iusto odio dignissimos ducimus qui blanditiis praesentium voluptatum deleniti atque corrupti quos dolores et quas molestias excepturi sint occaecati cupiditate non provident, similique sunt in culpa qui officia deserunt mollitia animi, id est laborum et dolorum fuga. Et harum quidem rerum facilis est et expedita distinctio. Nam libero tempore, cum soluta nobis est eligendi optio cumque nihil impedit quo minus id quod maxime placeat facere possimus, omnis voluptas assumenda est, omnis dolor repellendus. Temporibus autem quibusdam et aut officiis debitis aut rerum necessitatibus saepe eveniet ut et voluptates repudiandae sint et molestiae non recusandae. Itaque earum rerum hic tenetur a sapiente delectus, ut aut reiciendis voluptatibus maiores alias consequatur aut perferendis doloribus asperiores repellat."</p>
<p>1914 translation by H. Rackham<br />
"On the other hand, we denounce with righteous indignation and dislike men who are so beguiled and demoralized by the charms of pleasure of the moment, so blinded by desire, that they cannot foresee the pain and trouble that are bound to ensue; and equal blame belongs to those who fail in their duty through weakness of will, which is the same as saying through shrinking from toil and pain. These cases are perfectly simple and easy to distinguish. In a free hour, when our power of choice is untrammelled and when nothing prevents our being able to do what we like best, every pleasure is to be welcomed and every pain avoided. But in certain circumstances and owing to the claims of duty or the obligations of business it will frequently occur that pleasures have to be repudiated and annoyances accepted. The wise man therefore always holds in these matters to this principle of selection: he rejects pleasures to secure other greater pleasures, or else he endures pains to avoid worse pains."</p>
<p>안녕하세요? 정리하는 개발자 워니즈입니다. 이번 시간에는 <strong>클로드 에이전트 협업의 기술</strong>을 읽고 서평을 하도록 하겠습니다.</p>
<p>필자는 요즘 개인 블로그 운영을 상당 부분 클로드 에이전트에게 맡겨두고 있는데요. 글 초안을 만들고 발행 전 검사를 돌리고 소셜에 올리는 일까지 하루 네 번 자동으로 돌아가게 해두었습니다. 그런데 막상 굴려보니 도구를 붙이는 것보다 <strong>어떤 일을 누구에게 맡길지 정하는 쪽이 훨씬 어렵다</strong>는 걸 알게 됐습니다. 이 책이 다루는 게 정확히 그 지점이라 관심이 갔습니다.</p>
<p>책은 클로드 에이전트를 질문 상대가 아니라 <strong>업무를 위임받는 팀원</strong>으로 다루는 능력을 기르는 데 목표를 두고 있는데요. 챗봇 한 명에게 일일이 지시하던 방식을 끝내고 클로드 코워크와 클로드 코드라는 두 도구로 10명분의 AI 팀을 운영하는 것을 최종 그림으로 제시합니다.</p>
<p>그러면 본격적으로 각 단원별 내용을 정리하고 서평하도록 하겠습니다.<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/08/claude-agent-collaboration-cover.png?w=1200&#038;ssl=1" alt="클로드 에이전트 협업의 기술 책 표지" /></p>
<h2>목차</h2>
<h3>Part 00. AI 팀플레이의 시대가 열리다</h3>
<ul>
<li><strong>0.1 인류는 협력으로 문명을 만들었다</strong>
  </li>
<li><strong>0.2 &#8216;혼자 일하는 AI&#8217;에서 &#8216;팀으로 일하는 AI&#8217;로</strong>
  </li>
<li><strong>0.3 왜 클로드인가: 코워크와 코드, 두 개의 출발점</strong>
  </li>
<li><strong>0.4 이 책의 목표: 나만의 AI 조직도 만들기</strong>
  </li>
</ul>
<h3>Part 01. 클로드 코워크: 나의 첫 번째 에이전트 팀</h3>
<ul>
<li><strong>Chapter 01. 시작하기: 5분 안에 세팅하기</strong>
  </li>
<li><strong>Chapter 02. 에이전트에 첫 번째 일 맡기기</strong>
  </li>
<li><strong>Chapter 03. 에이전트의 능력을 확장하다: 멀티 파일 처리</strong>
  </li>
<li><strong>Chapter 04. 커넥터: 에이전트에게 손과 발 달아주기</strong>
  </li>
<li><strong>Chapter 05. 스킬: 에이전트에 전문성 부여하기</strong>
  </li>
<li><strong>Chapter 06. 플러그인: 에이전트 업무의 묶음을 만들다</strong>
  </li>
<li><strong>Chapter 07. 예약 작업으로 100% 자동화 에이전트 만들기</strong>
  </li>
</ul>
<h3>Part 02. 클로드 코드: 에이전트 군단을 지휘하라</h3>
<ul>
<li><strong>Chapter 08. 클로드 코드에 입장하기</strong>
  </li>
<li><strong>Chapter 09. 명령어 체계: 에이전트에게 지시하는 언어</strong>
  </li>
<li><strong>Chapter 10. CLAUDE.md: 에이전트의 업무 매뉴얼</strong>
  </li>
<li><strong>Chapter 11. 커스텀 명령어: 나만의 지휘 체계 만들기</strong>
  </li>
<li><strong>Chapter 12. MCP 서버: 에이전트의 활동 반경 넓히기</strong>
  </li>
<li><strong>Chapter 13. 서브 에이전트: AI가 AI를 부린다</strong>
  </li>
<li><strong>Chapter 14. 멀티 에이전트 오케스트레이션: 나만의 AI 조직도 구축하기</strong>
  </li>
<li><strong>Chapter 15. 멀티 에이전트 실전 I: PPT 자동화 에이전트 팀 만들기</strong>
  </li>
<li><strong>Chapter 16. 멀티 에이전트 실전 II: AI 콘텐츠 마케팅 에이전시 만들기</strong>
  </li>
<li><strong>Chapter 17. 에이전트 조직 운영의 기술</strong>
  </li>
</ul>
<h2>클로드 에이전트를 팀으로 굴리는 법, 챕터별 간단 서평</h2>
<h3>[Part 00 AI 팀플레이의 시대가 열리다]</h3>
<p>챗봇과 에이전트와 멀티 에이전트가 어떻게 다른지를 먼저 정리하고 들어가는데요. 용어를 느슨하게 쓰다 보면 &#8220;AI에게 맡긴다&#8221;는 말이 실제로 무엇을 맡긴다는 것인지 흐려지기 때문에, 이 구분을 앞에 두는 편성은 적절해 보였습니다. 클로드 코워크와 클로드 코드를 두 개의 출발점으로 나눠 소개하는 것도 이 책의 뼈대를 이해하는 데 도움이 됐습니다.</p>
<p><strong>이 장에서 배운 것</strong>: 도구를 쓰고 스스로 판단하면 클로드 에이전트 같은 에이전트이고, 그런 에이전트가 여럿 모여 역할을 나누면 멀티 에이전트입니다.</p>
<hr />
<h3>[Part 01 클로드 코워크: 나의 첫 번째 에이전트 팀]</h3>
<h4>Chapter 01 ~ 03. 세팅과 첫 위임, 그리고 멀티 파일 처리</h4>
<p>터미널을 쓰지 않는 독자를 위한 진입 구간입니다. 5분 세팅에서 시작해 첫 업무를 맡겨보고 여러 파일을 한 번에 다루는 데까지 올라가는데요. 난이도를 계단식으로 올려두어서 부담이 적었습니다.</p>
<p><strong>이 장에서 배운 것</strong>: 에이전트에게 일을 맡기는 첫 단계는 도구 설정이 아니라 <strong>맡길 일의 범위를 문장으로 적어보는 것</strong>입니다.</p>
<h4>Chapter 04. 커넥터: 에이전트에게 손과 발 달아주기</h4>
<p>에이전트가 외부 서비스에 실제로 접근하게 만드는 장입니다. 여기부터 &#8220;답변을 받는다&#8221;에서 &#8220;일이 처리된다&#8221;로 성격이 바뀌는데요. 필자도 블로그 자동화를 붙이면서 같은 전환점을 겪었기 때문에 공감이 갔습니다.</p>
<p><strong>이 장에서 배운 것</strong>: 커넥터를 붙이는 순간부터는 결과를 <strong>되돌릴 수 있는지</strong> 먼저 따져야 합니다.</p>
<h4>Chapter 05. 스킬: 에이전트에 전문성 부여하기</h4>
<p>빌트인, 커스텀, 파트너 세 가지 스킬 유형을 구분하고 <code>SKILL.md</code>를 직접 작성해보는 장입니다. 난이도는 별 두 개, 예상 학습 시간은 40분으로 표시돼 있는데요. 필자는 이 부분이 이 책에서 가장 실용적인 대목이라고 느꼈습니다. 같은 지시를 매번 반복해 설명하는 대신 파일 하나로 굳혀두는 방식이라, 실제로 자주 하는 작업이 있다면 바로 효과가 납니다.</p>
<p><strong>이 장에서 배운 것</strong>: 반복해서 설명하고 있는 작업이 있다면 그건 스킬로 만들어야 할 신호입니다.</p>
<h4>Chapter 06 ~ 07. 플러그인과 예약 작업</h4>
<p>플러그인으로 업무 묶음을 만들고, 예약 작업으로 사람 없이 돌아가게 만드는 구간입니다. 7장은 예약 작업의 <strong>한계와 대응 방법</strong>까지 학습 목표에 넣어둔 점이 눈에 띄었는데요. 자동 실행은 잘 도는 경우보다 안 도는 경우를 어떻게 알아채느냐에서 운영이 갈립니다. 필자도 하루 네 번 도는 작업이 조용히 실패해서 한참 뒤에 알아챈 적이 있어서, 이 항목이 목차에 있다는 것만으로 신뢰가 갔습니다.</p>
<p><strong>이 장에서 배운 것</strong>: 예약 작업은 성공했을 때가 아니라 <strong>실패했을 때 어떻게 알 것인가</strong>를 같이 설계해야 합니다. 필자의 클로드 에이전트 자동 실행이 실제로 얼마나 자주 미끄러졌는지는 <a href="https://blog.wonizz.com/2026/08/22/ai-automation-completion-condition-reality/">성공률을 세어본 기록</a>에 남겨두었습니다.</p>
<hr />
<h3>[Part 02 클로드 코드: 에이전트 군단을 지휘하라]</h3>
<h4>Chapter 08 ~ 09. 입장과 명령어 체계</h4>
<p>터미널 기반 도구로 넘어가는 구간입니다. 명령어를 &#8220;에이전트에게 지시하는 언어&#8221;로 표현한 점이 인상적이었는데요. 도구 사용법이 아니라 <strong>의사소통 방식</strong>으로 접근하는 관점이 이 책 전체를 관통합니다.</p>
<p><strong>이 장에서 배운 것</strong>: 명령어를 외우는 것보다 지시가 어디까지 전달되는지 감을 잡는 편이 먼저입니다.</p>
<h4>Chapter 10. CLAUDE.md: 에이전트의 업무 매뉴얼</h4>
<p>에이전트가 매번 참조하는 규칙 파일을 다루는 장입니다. 필자가 실제로 가장 많이 손대는 파일이기도 한데요. 여기에 무엇을 적고 무엇을 적지 않을지가 결과 품질을 크게 좌우합니다. 규칙을 잔뜩 넣으면 오히려 서로 부딪히는 경우가 생기는데, 그 균형을 잡는 이야기가 담겨 있어 반가웠습니다.</p>
<p><strong>이 장에서 배운 것</strong>: <code>CLAUDE.md</code>는 많이 적는 파일이 아니라 <strong>충돌 없이 적는 파일</strong>입니다.</p>
<h4>Chapter 11 ~ 12. 커스텀 명령어와 MCP 서버</h4>
<p>반복 작업을 명령어로 굳히고, MCP로 에이전트가 닿을 수 있는 범위를 넓히는 구간입니다. MCP는 최근 관심이 높은 주제라 별도로 찾아보신 분도 많을 텐데요. 규격 자체가 궁금하다면 <a href="https://modelcontextprotocol.io/" target="_blank" rel="noopener">MCP 공식 문서</a>를 함께 보시면 좋고, 최근 로드맵은 <a href="https://blog.wonizz.com/2026/08/25/mcp-roadmap-5-areas-long-running-tasks/">MCP 로드맵을 정리한 글</a>에 따로 적어두었습니다. 이 책은 MCP 자체를 깊게 파기보다 <strong>에이전트 조직 안에서 어떤 역할을 하는지</strong>의 위치에 놓고 설명합니다.</p>
<p><strong>이 장에서 배운 것</strong>: MCP는 새로운 기능이라기보다 에이전트의 <strong>활동 반경을 넓히는 배관</strong>에 가깝습니다.</p>
<h4>Chapter 13. 서브 에이전트: AI가 AI를 부린다</h4>
<p>클로드 에이전트가 또 다른 에이전트를 부리는 지휘관과 실행자 구조를 이해하고, 어떤 상황에서 병렬로 나눠야 이득인지 판단하는 장입니다. 난이도 별 네 개, 예상 학습 시간 45분으로 이 책에서 무게가 실린 구간인데요. <code>AGENT.md</code>의 <code>model</code>, <code>tools</code>, <code>maxTurns</code> 같은 필드를 조정해 비용과 품질을 맞추는 이야기까지 들어 있습니다.</p>
<p>필자도 오늘 작업 중에 서로 독립적인 일 두 개를 서브 에이전트에 나눠 맡겨봤는데, 한쪽 결과에 결함이 있어서 수정 지시를 다시 내려야 했습니다. 그래서 <strong>맡기는 것보다 받은 결과를 검증하는 쪽이 진짜 일</strong>이라는 이 장의 문제의식이 남 얘기로 읽히지 않았습니다. 자동화를 돌려도 사람에게 남는 몫이 무엇인지는 <a href="https://blog.wonizz.com/2026/08/23/claude-code-automation-human-role/">따로 정리한 글</a>에 적어두었습니다.</p>
<p><strong>이 장에서 배운 것</strong>: 병렬로 맡길수록 <strong>완료 보고가 아니라 결과물을 직접 확인</strong>해야 합니다.</p>
<h4>Chapter 14. 멀티 에이전트 오케스트레이션: 나만의 AI 조직도 구축하기</h4>
<p>이 책의 정점에 해당하는 장입니다. <strong>팬아웃, 파이프라인, 경쟁 가설, 스웜</strong> 네 가지 설계 패턴을 구분하고 업무에 맞는 것을 고르게 하는데요. 필자는 이 네 가지를 이름으로 정리해준 것만으로도 값어치가 있다고 느꼈습니다. 그동안 상황에 따라 감으로 나눠 맡기던 것을 부를 이름이 생기니 선택이 훨씬 명확해집니다.</p>
<p>에이전트끼리 소통하는 방식을 파일 기반, 체이닝, 에이전트 팀으로 나눠 설명하는 부분도 유용했습니다. 자동화가 커질수록 결국 걸리는 지점이 <strong>결과를 어디에 남기고 누가 읽느냐</strong>인데, 그 선택지를 정리해두었습니다.</p>
<p><strong>이 장에서 배운 것</strong>: 독립적인 작업이면 팬아웃, 순서가 있으면 파이프라인, 정답이 불확실하면 경쟁 가설로 나눕니다.</p>
<h4>Chapter 15 ~ 16. 멀티 에이전트 실전 두 가지</h4>
<p>PPT 자동화 팀과 콘텐츠 마케팅 에이전시를 직접 만들어보는 실습 구간입니다. 개념만 설명하고 끝나는 책이 많은데 여기서는 완성된 조직도 두 개를 끝까지 따라가게 해둔 점이 좋았습니다. 자기 직무에 맞게 변형할 출발점으로 쓰기 좋아 보였습니다.</p>
<p><strong>이 장에서 배운 것</strong>: 조직도는 처음부터 크게 그리는 것이 아니라 <strong>일 하나를 끝까지 돌려본 뒤 늘리는 것</strong>입니다.</p>
<h4>Chapter 17. 에이전트 조직 운영의 기술</h4>
<p>만든 다음의 이야기를 다루는 장이라 개인적으로 가장 반가웠습니다. 아침 브리핑부터 퇴근 보고까지의 하루 운영 루틴, <code>CLAUDE.md</code> 버전 관리로 하는 온보딩, 결과물 품질 체크 루틴, 그리고 비용 최적화가 차례로 나오는데요.</p>
<p>특히 <strong>&#8220;Opus는 팀장에게, Sonnet은 실무자에게&#8221;</strong> 라는 절 제목을 보고 웃었습니다. 필자가 실제로 쓰고 있는 방식과 같아서인데요. 판단이 필요한 자리에는 무거운 모델을, 지시가 명확한 정형 작업에는 가벼운 모델을 붙이는 것이 비용과 품질을 함께 잡는 현실적인 타협점입니다. 트러블슈팅 절을 따로 둔 것도 실제 운영을 해본 사람이 쓴 목차라는 인상을 줬습니다.</p>
<p><strong>이 장에서 배운 것</strong>: 에이전트 조직은 만드는 비용보다 <strong>운영하고 고치는 비용</strong>이 더 듭니다.</p>
<h2>서평</h2>
<h3>누가 읽으면 좋은가</h3>
<ul>
<li>AI 챗봇을 1년 이상 써왔지만 결국 내가 다 해야 한다는 한계를 느끼는 직장인
  </li>
<li>AI 자동화 시스템을 직접 설계해보고 싶은 3~10년 차 기획자, 마케터, 운영자
  </li>
<li>터미널이 낯설지 않고 클로드 코드의 제어권을 더 확보하고 싶은 분
  </li>
</ul>
<p>책이 밝히고 있는 대상 독자인데요. 클로드 에이전트를 처음 붙여보는 분부터 이미 굴리고 있는 분까지, 읽어보니 실제로 그 범위에 잘 맞습니다. 개발자만을 위한 책은 아니고, Part 01은 터미널 없이 따라갈 수 있게 구성돼 있어서 비개발 직군도 앞부분만으로 충분히 얻어갈 것이 있습니다.</p>
<h3>책의 주요 장점</h3>
<ol>
<li><strong>장마다 학습 목표와 난이도, 예상 학습 시간이 붙어 있습니다</strong>
<ul>
<li>별점 난이도와 분 단위 시간이 표시돼 있어 어디에 힘을 쓸지 미리 고를 수 있습니다</li>
<li>시간이 없을 때 필요한 장만 골라 읽기 좋은 구조입니다</li>
</ul>
</li>
<li><strong>설계 패턴에 이름을 붙여줍니다</strong>
<ul>
<li>팬아웃, 파이프라인, 경쟁 가설, 스웜이라는 이름이 생기면 상황마다 무엇을 고를지가 분명해집니다</li>
<li>감으로 나눠 맡기던 일을 언어로 정리하게 해주는 것이 이 책의 큰 기여라고 생각합니다</li>
</ul>
</li>
<li><strong>만든 다음의 이야기가 있습니다</strong>
<ul>
<li>17장 전체가 운영, 비용, 품질 체크, 트러블슈팅에 할애돼 있습니다</li>
<li>자동화 책이 대개 구축까지만 다루고 끝나는 것과 대비됩니다</li>
</ul>
</li>
<li><strong>두 도구를 하나의 흐름으로 엮습니다</strong>
<ul>
<li>클로드 코워크에서 시작해 클로드 코드로 넘어가는 순서라 진입 장벽이 완만합니다</li>
<li>도구별 매뉴얼이 아니라 조직을 만들어가는 이야기로 읽힙니다</li>
</ul>
</li>
</ol>
<p>클로드 에이전트를 여러 개 굴려본 입장에서 읽고 나서 가장 크게 남은 것은 <strong>에이전트를 늘리는 일보다 검증하고 운영하는 일이 본체</strong>라는 감각이었습니다. 클로드 에이전트를 한 번이라도 붙여본 분이라면 아마 같은 지점에서 고개를 끄덕이실 것 같습니다.</p>
<hr />
<p>본 포스팅은 &#8220;<strong>한빛미디어 &lt;나는 리뷰어다> 활동을 위해서 책을 제공받아 작성된 서평입니다</strong>&#8220;</p>
<p>The post <a rel="nofollow" href="https://blog.wonizz.com/2026/08/26/claude-agent-collaboration-review/">[서평 작성] 클로드 에이전트 협업의 기술</a> appeared first on <a rel="nofollow" href="https://blog.wonizz.com">WONIZZ.LOG</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.wonizz.com/2026/08/26/claude-agent-collaboration-review/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3372</post-id>	</item>
		<item>
		<title>[AI Now] AI 자동화 성공률 29%, 실패 원인 분석</title>
		<link>https://blog.wonizz.com/2026/08/22/ai-automation-completion-condition-reality/</link>
					<comments>https://blog.wonizz.com/2026/08/22/ai-automation-completion-condition-reality/#respond</comments>
		
		<dc:creator><![CDATA[워니즈]]></dc:creator>
		<pubDate>Fri, 21 Aug 2026 22:59:53 +0000</pubDate>
				<category><![CDATA[AI Now]]></category>
		<category><![CDATA[AI 검증]]></category>
		<category><![CDATA[AI 에이전트]]></category>
		<category><![CDATA[AI 자동화]]></category>
		<guid isPermaLink="false">https://blog.wonizz.com/2026/08/22/ai-automation-completion-condition-reality/</guid>

					<description><![CDATA[<p>The standard Lorem Ipsum passage, used since the 1500s<br />
"Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum."</p>
<p>Section 1.10.32 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"Sed ut perspiciatis unde omnis iste natus error sit voluptatem accusantium doloremque laudantium, totam rem aperiam, eaque ipsa quae ab illo inventore veritatis et quasi architecto beatae vitae dicta sunt explicabo. Nemo enim ipsam voluptatem quia voluptas sit aspernatur aut odit aut fugit, sed quia consequuntur magni dolores eos qui ratione voluptatem sequi nesciunt. Neque porro quisquam est, qui dolorem ipsum quia dolor sit amet, consectetur, adipisci velit, sed quia non numquam eius modi tempora incidunt ut labore et dolore magnam aliquam quaerat voluptatem. Ut enim ad minima veniam, quis nostrum exercitationem ullam corporis suscipit laboriosam, nisi ut aliquid ex ea commodi consequatur? Quis autem vel eum iure reprehenderit qui in ea voluptate velit esse quam nihil molestiae consequatur, vel illum qui dolorem eum fugiat quo voluptas nulla pariatur?"</p>
<p>1914 translation by H. Rackham<br />
"But I must explain to you how all this mistaken idea of denouncing pleasure and praising pain was born and I will give you a complete account of the system, and expound the actual teachings of the great explorer of the truth, the master-builder of human happiness. No one rejects, dislikes, or avoids pleasure itself, because it is pleasure, but because those who do not know how to pursue pleasure rationally encounter consequences that are extremely painful. Nor again is there anyone who loves or pursues or desires to obtain pain of itself, because it is pain, but because occasionally circumstances occur in which toil and pain can procure him some great pleasure. To take a trivial example, which of us ever undertakes laborious physical exercise, except to obtain some advantage from it? But who has any right to find fault with a man who chooses to enjoy a pleasure that has no annoying consequences, or one who avoids a pain that produces no resultant pleasure?"</p>
<p>Section 1.10.33 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"At vero eos et accusamus et iusto odio dignissimos ducimus qui blanditiis praesentium voluptatum deleniti atque corrupti quos dolores et quas molestias excepturi sint occaecati cupiditate non provident, similique sunt in culpa qui officia deserunt mollitia animi, id est laborum et dolorum fuga. Et harum quidem rerum facilis est et expedita distinctio. Nam libero tempore, cum soluta nobis est eligendi optio cumque nihil impedit quo minus id quod maxime placeat facere possimus, omnis voluptas assumenda est, omnis dolor repellendus. Temporibus autem quibusdam et aut officiis debitis aut rerum necessitatibus saepe eveniet ut et voluptates repudiandae sint et molestiae non recusandae. Itaque earum rerum hic tenetur a sapiente delectus, ut aut reiciendis voluptatibus maiores alias consequatur aut perferendis doloribus asperiores repellat."</p>
<p>1914 translation by H. Rackham<br />
"On the other hand, we denounce with righteous indignation and dislike men who are so beguiled and demoralized by the charms of pleasure of the moment, so blinded by desire, that they cannot foresee the pain and trouble that are bound to ensue; and equal blame belongs to those who fail in their duty through weakness of will, which is the same as saying through shrinking from toil and pain. These cases are perfectly simple and easy to distinguish. In a free hour, when our power of choice is untrammelled and when nothing prevents our being able to do what we like best, every pleasure is to be welcomed and every pain avoided. But in certain circumstances and owing to the claims of duty or the obligations of business it will frequently occur that pleasures have to be repudiated and annoyances accepted. The wise man therefore always holds in these matters to this principle of selection: he rejects pleasures to secure other greater pleasures, or else he endures pains to avoid worse pains."</p>
<p>title: [AI Now] AI 자동화 6일 돌려보니 성공률 29%였습니다</p>
<p>The post <a rel="nofollow" href="https://blog.wonizz.com/2026/08/22/ai-automation-completion-condition-reality/">[AI Now] AI 자동화 성공률 29%, 실패 원인 분석</a> appeared first on <a rel="nofollow" href="https://blog.wonizz.com">WONIZZ.LOG</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The standard Lorem Ipsum passage, used since the 1500s<br />
"Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum."</p>
<p>Section 1.10.32 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"Sed ut perspiciatis unde omnis iste natus error sit voluptatem accusantium doloremque laudantium, totam rem aperiam, eaque ipsa quae ab illo inventore veritatis et quasi architecto beatae vitae dicta sunt explicabo. Nemo enim ipsam voluptatem quia voluptas sit aspernatur aut odit aut fugit, sed quia consequuntur magni dolores eos qui ratione voluptatem sequi nesciunt. Neque porro quisquam est, qui dolorem ipsum quia dolor sit amet, consectetur, adipisci velit, sed quia non numquam eius modi tempora incidunt ut labore et dolore magnam aliquam quaerat voluptatem. Ut enim ad minima veniam, quis nostrum exercitationem ullam corporis suscipit laboriosam, nisi ut aliquid ex ea commodi consequatur? Quis autem vel eum iure reprehenderit qui in ea voluptate velit esse quam nihil molestiae consequatur, vel illum qui dolorem eum fugiat quo voluptas nulla pariatur?"</p>
<p>1914 translation by H. Rackham<br />
"But I must explain to you how all this mistaken idea of denouncing pleasure and praising pain was born and I will give you a complete account of the system, and expound the actual teachings of the great explorer of the truth, the master-builder of human happiness. No one rejects, dislikes, or avoids pleasure itself, because it is pleasure, but because those who do not know how to pursue pleasure rationally encounter consequences that are extremely painful. Nor again is there anyone who loves or pursues or desires to obtain pain of itself, because it is pain, but because occasionally circumstances occur in which toil and pain can procure him some great pleasure. To take a trivial example, which of us ever undertakes laborious physical exercise, except to obtain some advantage from it? But who has any right to find fault with a man who chooses to enjoy a pleasure that has no annoying consequences, or one who avoids a pain that produces no resultant pleasure?"</p>
<p>Section 1.10.33 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"At vero eos et accusamus et iusto odio dignissimos ducimus qui blanditiis praesentium voluptatum deleniti atque corrupti quos dolores et quas molestias excepturi sint occaecati cupiditate non provident, similique sunt in culpa qui officia deserunt mollitia animi, id est laborum et dolorum fuga. Et harum quidem rerum facilis est et expedita distinctio. Nam libero tempore, cum soluta nobis est eligendi optio cumque nihil impedit quo minus id quod maxime placeat facere possimus, omnis voluptas assumenda est, omnis dolor repellendus. Temporibus autem quibusdam et aut officiis debitis aut rerum necessitatibus saepe eveniet ut et voluptates repudiandae sint et molestiae non recusandae. Itaque earum rerum hic tenetur a sapiente delectus, ut aut reiciendis voluptatibus maiores alias consequatur aut perferendis doloribus asperiores repellat."</p>
<p>1914 translation by H. Rackham<br />
"On the other hand, we denounce with righteous indignation and dislike men who are so beguiled and demoralized by the charms of pleasure of the moment, so blinded by desire, that they cannot foresee the pain and trouble that are bound to ensue; and equal blame belongs to those who fail in their duty through weakness of will, which is the same as saying through shrinking from toil and pain. These cases are perfectly simple and easy to distinguish. In a free hour, when our power of choice is untrammelled and when nothing prevents our being able to do what we like best, every pleasure is to be welcomed and every pain avoided. But in certain circumstances and owing to the claims of duty or the obligations of business it will frequently occur that pleasures have to be repudiated and annoyances accepted. The wise man therefore always holds in these matters to this principle of selection: he rejects pleasures to secure other greater pleasures, or else he endures pains to avoid worse pains."</p>
안녕하세요? 정리하는 개발자 워니즈입니다.

<strong>개인 블로그를 사람 손 없이 돌려보려고 자동 실행 슬롯을 걸어두고 엿새 동안의 실행 기록을 세어봤더니, 예정된 17개 슬롯 가운데 끝까지 정상 종료된 것은 5개뿐이었습니다. 성공률 29%. 그런데 정작 실패의 대부분은 필자가 짠 자동화 코드 안쪽이 아니라 그 밖에서 나 있었습니다.</strong> 완료 조건을 문장으로 적어두면 그다음은 알아서 돌아갈 것이라고 여기고 있었는데 실제로는 완료 조건에 도달할 기회조차 못 얻은 슬롯이 훨씬 많았던 셈입니다.

앞으로 지킬 기준을 한 줄로 줄이면 이렇습니다. <strong>완료 조건을 정하는 데서 멈추지 않고 무엇을 실패로 셀 것인지까지 같은 자리에 적어둡니다.</strong>

<ul>
  <li>무엇을 쟀는가: AI 자동화 슬롯 17개의 실행 기록을 상태별로 하나씩 분류했습니다.</li>
  <li>무엇이 예상과 달랐는가: 실패 12건 중 8건이 코드와 무관한 실행 환경 쪽이었고 기록조차 남지 않은 슬롯이 3건이었습니다.</li>
  <li>그래서 무엇을 바꿨는가: 실패 분류를 먼저 정의하고 검사기 자체에도 회귀 테스트를 붙였습니다.</li>
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/08/patrol-success-rate-breakdown.png?w=1200&#038;ssl=1" alt="AI 자동화 슬롯 17개를 성공과 실패 유형별로 나눈 비교 그래프" />
</ul>

<h2>완료 조건만 적어두면 알아서 돌 거라고 여겼습니다</h2>

필자가 세워둔 장치는 정해진 시각에 스스로 깨어나서 글을 하나 내보내고 홍보와 점검까지 마친 다음 기록을 남기고 끝나는 구조였습니다. 각 단계마다 통과해야 할 조건을 미리 문장으로 적어두었기 때문에 이 정도면 사람이 안 봐도 굴러갈 것이라고 생각하고 있었습니다.

그런데 엿새가 지나고 실행 기록을 열어봤을 때 눈에 들어온 것은 조건을 못 넘긴 실행이 아니라 <strong>조건 앞까지 오지도 못한 실행</strong>이었습니다. 완료 조건이라는 개념은 어디까지나 실행이 시작된 뒤에 의미가 있는 장치입니다. 그런데 필자는 그 조건 하나로 자동화 전체의 신뢰성을 담보하려 하고 있었던 것 같습니다.

<h2>17개 슬롯 중 다섯 개만 끝까지 갔습니다</h2>

기록을 상태별로 세어보니 다음과 같이 갈렸습니다.

<figure class="wp-block-table">

<table><thead><tr><th>상태</th><th>슬롯 수</th><th>성격</th></tr></thead><tbody><tr><td>정상 종료</td><td>5</td><td>완료 조건까지 도달</td></tr><tr><td>사용량 한도로 실패</td><td>8</td><td>실행 환경 문제, 코드 수정으로 못 고침</td></tr><tr><td>자기 자신을 정지시킨 버그</td><td>1</td><td>자동화 코드 문제</td></tr><tr><td>시작 기록만 있고 끝이 없음</td><td>1</td><td>원인 불명, 사후 추적 불가</td></tr><tr><td>시작 기록 자체가 없음</td><td>2</td><td>위 버그의 파급, 아무 흔적도 안 남음</td></tr></tbody></table>

</figure>

이 표에서 필자가 제일 오래 들여다본 줄은 마지막 두 줄이었는데요 <strong>실패했다는 사실조차 기록으로 안 남은 슬롯이 3개</strong>였기 때문입니다. 자동화가 실패하면 로그에 실패가 찍힐 것이라는 전제 자체가 성립하지 않고 있었던 셈이고 그래서 필자는 며칠 동안 장치가 정상적으로 돌고 있다고 믿고 있었습니다. <a href="https://blog.wonizz.com/2026/08/20/blog-bot-traffic-analysis/">자동화된 요청과 사람의 방문이 총량 안쪽에서 섞여 있던 사례</a>를 정리해본 적이 있는데요 이번 것도 결국 같은 계열이었는데 합계만 보고 있으면 없는 것과 실패한 것이 구분되지 않습니다.

<h2>AI 자동화 실패는 왜 코드 밖에서 더 많이 났을까요?</h2>

실패 12건 중 8건이 사용량 한도 때문이었습니다. 필자가 대화형으로 작업을 하는 동안 같은 사용량을 무인 슬롯도 함께 쓰고 있었기 때문에 필자가 낮에 뭔가를 열심히 하면 저녁 슬롯이 조용히 죽는 구조였습니다. 자동화 코드에는 아무 잘못이 없었고 실제로 그 부분을 몇 번 손봤지만 성공률은 움직이지 않았습니다.

여기서 얻은 것은 대책보다 관점 쪽인데요 <strong>AI 자동화의 신뢰성은 코드 품질과 실행 자원 확보라는 두 축으로 나뉘어 있고 이 둘은 서로를 대신해주지 않는다</strong>는 것입니다. 코드를 완벽하게 만들어도 자원을 못 잡으면 실행이 안 되고 자원이 넉넉해도 코드가 자기를 끄면 역시 안 됩니다. 필자는 그동안 첫 번째 축만 관리하면서 두 번째 축을 상수처럼 다루고 있었습니다.

GeekNews에 올라온 <a href="https://news.hada.io/topic?id=32519" target="_blank" rel="noopener">실전 루프 엔지니어링 요약</a>에서는 자율성보다 완료 조건과 제약을 명확히 정의하는 것이 핵심이라고 정리하면서 작업하는 쪽과 검증하는 쪽을 나누라고 권합니다. 필자의 실측을 여기에 겹쳐보면 한 층이 더 필요해 보입니다. 완료 조건과 검증을 나눠놓아도 <strong>실행이 시작됐는지 자체를 확인하는 층</strong>이 없으면 흔적 없는 실패가 그대로 성공처럼 보이게 됩니다.

<h2>검사기가 알려준 것은 증상뿐이었습니다</h2>

두 번째 교훈은 좀 뼈아팠는데요 필자는 발행 후 점검을 자동화해두었기 때문에 문제가 생기면 알림이 뜨도록 되어 있었고 실제로 알림은 정확하게 떴습니다. 사이트맵에 새 글이 안 들어가고 있다는 신호가 나흘 동안 매일 올라왔습니다.

문제는 그 신호를 받고 필자가 향한 곳이었는데요 <a href="https://blog.wonizz.com/2026/08/19/wordpress-sitemap-missing-posts/">사이트맵에 글이 빠졌던 사건을 정리한 글</a>에서 필자는 원인을 SEO 플러그인 쪽으로 지목했고 그 계층에서만 며칠을 만졌습니다. 뒤늦게 확인된 진범은 전혀 다른 곳에 있었습니다. 캐시 플러그인이 사이트맵 XML을 일반 페이지처럼 통째로 캐시해두고 있었기 때문에 요청이 애초에 원래 담당 코드까지 도달하지 못하고 있었습니다.

<blockquote>검사기는 무엇이 틀렸는지는 알려주지만 어느 계층에서 틀렸는지는 알려주지 않습니다. 검사 스코프와 결함 스코프가 어긋나 있으면 통과든 실패든 그 판정이 보장하는 범위는 생각보다 훨씬 좁습니다.</p></blockquote>

같은 축의 이야기를 <a href="https://news.hada.io/topic?id=32544" target="_blank" rel="noopener">Graph 엔지니어링과 Loop 엔지니어링을 비교한 글</a>에서도 읽었습니다. 여러 판정이 서로 합의한다고 해서 신뢰성이 올라가지는 않고 외부의 실제 증거가 필요하다는 대목이 필자 사례와 정확히 맞물렸습니다. 필자의 알림은 나흘 내내 같은 말을 반복하면서 서로 합의하고 있었지만 어느 계층인지를 밝혀줄 외부 증거는 하나도 만들어내지 못했습니다.

<h2>규칙이 열일곱 개인데 회귀 테스트가 0건이면 어떻게 될까요?</h2>

세 번째는 검사기 자체의 문제였는데요 필자의 발행 검사기는 사고가 날 때마다 규칙을 하나씩 붙이는 방식으로 자라나서 어느새 열일곱 개가 되어 있었습니다. 그런데 이 규칙들을 고정해두는 회귀 테스트가 한 건도 없었습니다.

문제가 드러난 순간은 규칙 하나를 되돌릴 때였습니다. 되돌린 규칙 때문에 다른 규칙이 정상 제목까지 전부 걸러내기 시작했고 그것을 손으로 몇 번 넣어보다가 겨우 알아챘습니다. 검사기가 늘어날수록 규칙끼리 간섭할 여지도 같이 늘어나는데 정작 그 간섭을 잡아줄 장치는 없었던 셈입니다. <a href="https://blog.wonizz.com/2026/08/21/ai-code-review-gap/">검사기를 믿었을 때 생기는 함정들을 따로 정리해둔 글</a>이 있는데 이번 건은 그 목록에 하나를 더 보태는 사례였던 것 같습니다.

그래서 검사기에도 테스트를 붙였는데요 막아야 할 나쁜 사례뿐 아니라 <strong>통과해야 하는 정상 사례까지 함께 고정</strong>하는 것이 핵심이었습니다. 나쁜 사례만 모아두면 규칙을 세게 조일 때 정상 원고까지 막히는 쪽은 계속 열려 있게 됩니다.

이렇게 정리해보니 필자가 엿새 동안 실제로 만들고 있던 것은 자동화가 아니라 <strong>자동화를 감시하는 층</strong>이었던 셈입니다. 완료 조건은 그 층의 첫 칸일 뿐이고 실행이 시작됐는지, 실패가 기록으로 남는지, 판정을 내리는 장치 자체가 아직 멀쩡한지까지 세 칸이 더 필요했습니다. 앞의 세 가지 교훈이 서로 다른 사고처럼 보였지만 결국 같은 자리를 가리키고 있었는데 판단을 자동화에 넘겨준 만큼 그 판단이 여전히 작동하는지를 확인하는 몫이 필자 쪽으로 넘어와 있었습니다. 위에서 인용한 요약글에서도 작업은 위임해도 판단까지 위임하지는 말라고 적어두었습니다. 필자는 그 문장을 읽고서도 판단하는 장치를 만들어둔 것으로 판단을 지킨 셈이라고 넘기고 있었습니다.

<h2>정리</h2>

<ul>
  <li>AI 자동화 슬롯 17개 중 정상 종료는 <strong>5개로 성공률 29%</strong>였고 나머지는 완료 조건에 닿지도 못했습니다.</li>
  <li>실패 12건 중 <strong>8건이 사용량 한도</strong>라 코드 수정으로는 성공률이 움직이지 않았습니다. 신뢰성은 코드와 실행 자원 두 축으로 나뉘어 있었습니다.</li>
  <li><strong>3건은 실패 기록조차 남지 않았습니다.</strong> 로그에 실패가 찍힐 것이라는 전제부터 성립하지 않았습니다.</li>
  <li>검사기는 사이트맵 문제를 나흘 동안 정확히 알렸지만 <strong>원인 계층은 알려주지 않아서</strong> 필자는 엉뚱한 계층을 며칠 만졌습니다.</li>
  <li>규칙 열일곱 개짜리 검사기에 <strong>회귀 테스트가 0건</strong>이어서 규칙 하나를 되돌리다 다른 규칙이 조용히 깨질 뻔했습니다.</li>
  <li>그래서 완료 조건 문장 다음 줄에 <strong>무엇을 실패로 셀 것인지와 검사기 자체를 무엇으로 검증할 것인지</strong>를 같이 적기로 했습니다. <a href="https://blog.wonizz.com/2026/03/01/ai-agent-master-class/">에이전트에게 일을 맡기는 방식을 정리해본 글</a>을 쓸 때는 여기까지 생각이 닿지 못했는데요 위임의 난이도는 지시문보다 실패를 세는 쪽에 있었던 듯합니다.</li>
</ul>
<h2 class="wp-block-heading">함께 보면 좋은 글</h2>
<ul class="wp-block-list"><li><a href="https://blog.wonizz.com/2026/08/23/claude-code-automation-human-role/">[AI Now] Claude Code 자동화, 사람 몫 4가지</a></li><li><a href="https://blog.wonizz.com/2026/08/18/ai-completion-report-verification/">[AI Now] AI 완료 보고를 그대로 믿으면 생기는 일</a></li></ul><p>The post <a rel="nofollow" href="https://blog.wonizz.com/2026/08/22/ai-automation-completion-condition-reality/">[AI Now] AI 자동화 성공률 29%, 실패 원인 분석</a> appeared first on <a rel="nofollow" href="https://blog.wonizz.com">WONIZZ.LOG</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.wonizz.com/2026/08/22/ai-automation-completion-condition-reality/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3353</post-id>	</item>
		<item>
		<title>[AI Now] AI 완료 보고를 그대로 믿으면 생기는 일</title>
		<link>https://blog.wonizz.com/2026/08/18/ai-completion-report-verification/</link>
					<comments>https://blog.wonizz.com/2026/08/18/ai-completion-report-verification/#comments</comments>
		
		<dc:creator><![CDATA[워니즈]]></dc:creator>
		<pubDate>Mon, 17 Aug 2026 23:30:35 +0000</pubDate>
				<category><![CDATA[AI Now]]></category>
		<category><![CDATA[AI 검증]]></category>
		<category><![CDATA[AI 에이전트]]></category>
		<category><![CDATA[AI 자동화]]></category>
		<category><![CDATA[자동화 운영]]></category>
		<guid isPermaLink="false">https://blog.wonizz.com/2026/08/18/ai-completion-report-verification/</guid>

					<description><![CDATA[<p>The standard Lorem Ipsum passage, used since the 1500s<br />
"Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum."</p>
<p>Section 1.10.32 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"Sed ut perspiciatis unde omnis iste natus error sit voluptatem accusantium doloremque laudantium, totam rem aperiam, eaque ipsa quae ab illo inventore veritatis et quasi architecto beatae vitae dicta sunt explicabo. Nemo enim ipsam voluptatem quia voluptas sit aspernatur aut odit aut fugit, sed quia consequuntur magni dolores eos qui ratione voluptatem sequi nesciunt. Neque porro quisquam est, qui dolorem ipsum quia dolor sit amet, consectetur, adipisci velit, sed quia non numquam eius modi tempora incidunt ut labore et dolore magnam aliquam quaerat voluptatem. Ut enim ad minima veniam, quis nostrum exercitationem ullam corporis suscipit laboriosam, nisi ut aliquid ex ea commodi consequatur? Quis autem vel eum iure reprehenderit qui in ea voluptate velit esse quam nihil molestiae consequatur, vel illum qui dolorem eum fugiat quo voluptas nulla pariatur?"</p>
<p>1914 translation by H. Rackham<br />
"But I must explain to you how all this mistaken idea of denouncing pleasure and praising pain was born and I will give you a complete account of the system, and expound the actual teachings of the great explorer of the truth, the master-builder of human happiness. No one rejects, dislikes, or avoids pleasure itself, because it is pleasure, but because those who do not know how to pursue pleasure rationally encounter consequences that are extremely painful. Nor again is there anyone who loves or pursues or desires to obtain pain of itself, because it is pain, but because occasionally circumstances occur in which toil and pain can procure him some great pleasure. To take a trivial example, which of us ever undertakes laborious physical exercise, except to obtain some advantage from it? But who has any right to find fault with a man who chooses to enjoy a pleasure that has no annoying consequences, or one who avoids a pain that produces no resultant pleasure?"</p>
<p>Section 1.10.33 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"At vero eos et accusamus et iusto odio dignissimos ducimus qui blanditiis praesentium voluptatum deleniti atque corrupti quos dolores et quas molestias excepturi sint occaecati cupiditate non provident, similique sunt in culpa qui officia deserunt mollitia animi, id est laborum et dolorum fuga. Et harum quidem rerum facilis est et expedita distinctio. Nam libero tempore, cum soluta nobis est eligendi optio cumque nihil impedit quo minus id quod maxime placeat facere possimus, omnis voluptas assumenda est, omnis dolor repellendus. Temporibus autem quibusdam et aut officiis debitis aut rerum necessitatibus saepe eveniet ut et voluptates repudiandae sint et molestiae non recusandae. Itaque earum rerum hic tenetur a sapiente delectus, ut aut reiciendis voluptatibus maiores alias consequatur aut perferendis doloribus asperiores repellat."</p>
<p>1914 translation by H. Rackham<br />
"On the other hand, we denounce with righteous indignation and dislike men who are so beguiled and demoralized by the charms of pleasure of the moment, so blinded by desire, that they cannot foresee the pain and trouble that are bound to ensue; and equal blame belongs to those who fail in their duty through weakness of will, which is the same as saying through shrinking from toil and pain. These cases are perfectly simple and easy to distinguish. In a free hour, when our power of choice is untrammelled and when nothing prevents our being able to do what we like best, every pleasure is to be welcomed and every pain avoided. But in certain circumstances and owing to the claims of duty or the obligations of business it will frequently occur that pleasures have to be repudiated and annoyances accepted. The wise man therefore always holds in these matters to this principle of selection: he rejects pleasures to secure other greater pleasures, or else he endures pains to avoid worse pains."</p>
<p>작업을 맡긴 AI가 전부 끝냈다고 말했는데 몇 시간 뒤에 열어보니 절반만 되어 있던 경험이 있으신가요. 더 곤란한 건 AI 완료 보고 자체에는 아무런 흠이 없어 보여서, 무엇이 빠졌는지조차 한참 뒤에야 알아차리게 된다는 점인데요.</p>
<p>The post <a rel="nofollow" href="https://blog.wonizz.com/2026/08/18/ai-completion-report-verification/">[AI Now] AI 완료 보고를 그대로 믿으면 생기는 일</a> appeared first on <a rel="nofollow" href="https://blog.wonizz.com">WONIZZ.LOG</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The standard Lorem Ipsum passage, used since the 1500s<br />
"Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum."</p>
<p>Section 1.10.32 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"Sed ut perspiciatis unde omnis iste natus error sit voluptatem accusantium doloremque laudantium, totam rem aperiam, eaque ipsa quae ab illo inventore veritatis et quasi architecto beatae vitae dicta sunt explicabo. Nemo enim ipsam voluptatem quia voluptas sit aspernatur aut odit aut fugit, sed quia consequuntur magni dolores eos qui ratione voluptatem sequi nesciunt. Neque porro quisquam est, qui dolorem ipsum quia dolor sit amet, consectetur, adipisci velit, sed quia non numquam eius modi tempora incidunt ut labore et dolore magnam aliquam quaerat voluptatem. Ut enim ad minima veniam, quis nostrum exercitationem ullam corporis suscipit laboriosam, nisi ut aliquid ex ea commodi consequatur? Quis autem vel eum iure reprehenderit qui in ea voluptate velit esse quam nihil molestiae consequatur, vel illum qui dolorem eum fugiat quo voluptas nulla pariatur?"</p>
<p>1914 translation by H. Rackham<br />
"But I must explain to you how all this mistaken idea of denouncing pleasure and praising pain was born and I will give you a complete account of the system, and expound the actual teachings of the great explorer of the truth, the master-builder of human happiness. No one rejects, dislikes, or avoids pleasure itself, because it is pleasure, but because those who do not know how to pursue pleasure rationally encounter consequences that are extremely painful. Nor again is there anyone who loves or pursues or desires to obtain pain of itself, because it is pain, but because occasionally circumstances occur in which toil and pain can procure him some great pleasure. To take a trivial example, which of us ever undertakes laborious physical exercise, except to obtain some advantage from it? But who has any right to find fault with a man who chooses to enjoy a pleasure that has no annoying consequences, or one who avoids a pain that produces no resultant pleasure?"</p>
<p>Section 1.10.33 of "de Finibus Bonorum et Malorum", written by Cicero in 45 BC<br />
"At vero eos et accusamus et iusto odio dignissimos ducimus qui blanditiis praesentium voluptatum deleniti atque corrupti quos dolores et quas molestias excepturi sint occaecati cupiditate non provident, similique sunt in culpa qui officia deserunt mollitia animi, id est laborum et dolorum fuga. Et harum quidem rerum facilis est et expedita distinctio. Nam libero tempore, cum soluta nobis est eligendi optio cumque nihil impedit quo minus id quod maxime placeat facere possimus, omnis voluptas assumenda est, omnis dolor repellendus. Temporibus autem quibusdam et aut officiis debitis aut rerum necessitatibus saepe eveniet ut et voluptates repudiandae sint et molestiae non recusandae. Itaque earum rerum hic tenetur a sapiente delectus, ut aut reiciendis voluptatibus maiores alias consequatur aut perferendis doloribus asperiores repellat."</p>
<p>1914 translation by H. Rackham<br />
"On the other hand, we denounce with righteous indignation and dislike men who are so beguiled and demoralized by the charms of pleasure of the moment, so blinded by desire, that they cannot foresee the pain and trouble that are bound to ensue; and equal blame belongs to those who fail in their duty through weakness of will, which is the same as saying through shrinking from toil and pain. These cases are perfectly simple and easy to distinguish. In a free hour, when our power of choice is untrammelled and when nothing prevents our being able to do what we like best, every pleasure is to be welcomed and every pain avoided. But in certain circumstances and owing to the claims of duty or the obligations of business it will frequently occur that pleasures have to be repudiated and annoyances accepted. The wise man therefore always holds in these matters to this principle of selection: he rejects pleasures to secure other greater pleasures, or else he endures pains to avoid worse pains."</p>
작업을 맡긴 AI가 전부 끝냈다고 말했는데 몇 시간 뒤에 열어보니 절반만 되어 있던 경험이 있으신가요. 더 곤란한 건 AI 완료 보고 자체에는 아무런 흠이 없어 보여서, 무엇이 빠졌는지조차 한참 뒤에야 알아차리게 된다는 점인데요.

정리하는 개발자 워니즈입니다. 이번시간에는 필자가 개인 블로그의 발행과 소셜 게시, 지표 기록을 AI에게 맡겨 자동으로 굴리면서 실제로 겪은 사건 세 가지를 늘어놓고, AI 완료 보고를 어디까지 믿어도 되는지 정리해보려고 합니다. 미리 말씀드리면 완료 보고란 작업이 끝났다는 증거가 아니라 끝났다고 판단했다는 진술에 가까워서, 그 진술과 사실 사이를 메우는 건 결국 검사 한 줄인 것 같습니다.
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/blog.wonizz.com/wp-content/uploads/2026/08/completion-report-diagram.png?w=1200&#038;ssl=1" alt="AI 완료 보고와 실제 상태가 어긋난 세 가지 실측 수치" />

<h2>사건 하나, 눈에 보이는 일만 끝나 있었습니다</h2>

2026년 8월 17일에 필자는 AI 세션 하나에 글 세 편의 발행과 소셜 게시까지 맡겼고, 돌아온 보고는 규격대로 전부 마쳤다는 깔끔한 내용이었는데요. 저녁에 직접 점검해보니 발행과 게시처럼 눈에 보이는 작업은 실제로 다 되어 있었지만, 운영 일지 갱신과 글감 소진 표기, SEO 점수 기록처럼 눈에 보이지 않는 기록 작업은 통째로 빠져 있었습니다. SEO 점수는 세 편 전부 미기록이었고 그 사실은 완료 보고 어디에서도 드러나지 않았습니다.

여기서 흥미로웠던 건 AI가 없는 사실을 지어내지는 않았다는 점입니다. 발행이라는 주된 목표는 정확하게 달성했고 다만 그 목표에 딸려 있던 부수 절차를 스스로 완료의 조건에서 빼버린 쪽에 가까운데요. 마감이 급하면 사람도 똑같이 하는 일이라서, 이건 정직성의 문제가 아니라 완료의 경계를 누가 그었느냐의 문제라고 봐야 할 것 같습니다.

<h2>사건 둘, 올렸다는 글이 어디에도 없었습니다</h2>

두 번째는 소셜 게시였습니다. Threads에 글을 올렸다는 완료 보고를 받았는데 실제로는 그 글이 어디에도 없었고, 뒤늦게 원인을 확인해보니 작성창이 인라인 모드로 열렸을 때는 게시 버튼 자체가 존재하지 않아서 입력한 내용이 그대로 사라져버린 것이었습니다. 입력까지는 분명히 성공했으니 자동화 입장에서는 실패한 흔적조차 남지 않았던 셈인데요.

그 뒤로는 게시가 끝나면 프로필 목록과 permalink를 다시 조회해서 그 글이 실제로 존재하는지 확인한 다음에만 완료로 치는 규칙을 넣었습니다. 규칙을 문서에 적어두는 것만으로는 반드시 새어 나가기 때문에 검사 형태로 바꿔야 한다는 이야기는 <a href="https://blog.wonizz.com/2026/08/17/ai-rules-need-gates/">규칙을 문서가 아니라 검사로 만든 기록</a>에 따로 정리해뒀습니다.

<h2>사건 셋, 명령은 성공했고 화면은 그대로였습니다</h2>

세 번째는 캐시였습니다. 새 글을 올린 뒤 캐시를 비우는 명령을 실행하면 성공 응답이 멀쩡하게 돌아오는데, 정작 홈 화면에는 새 글이 나타나지 않는 경우가 있었습니다. 명령이 성공했다는 사실과 사용자가 보는 상태가 바뀌었다는 사실은 서로 다른 층위에 있는데, 자동화는 앞의 것만 확인하고 완료를 선언하기 아주 쉬운 구조인데요.

그래서 지금은 캐시를 비운 다음 홈 HTML을 다시 받아 새 글 주소가 실제로 들어 있는지 grep으로 확인하고 나서야 다음 단계로 넘어갑니다. 이 증상을 처음 숫자로 재봤던 과정은 <a href="https://blog.wonizz.com/2026/08/16/wordpress-new-post-not-showing-home-cache/">새 글이 홈에만 안 보였던 기록</a>에 응답 크기 차이까지 함께 남겨뒀습니다.

<h2>AI 완료 보고를 다루는 원칙 세 가지</h2>

사건 세 개를 나란히 늘어놓고 보니 공통점이 제법 뚜렷했고, 필자는 여기서 원칙 세 가지를 뽑아 자동화 절차에 그대로 박아뒀습니다. 첫째는 AI 완료 보고가 아니라 결과물의 존재를 실측한다는 것인데요. 보고 문장을 읽는 대신 결과가 있어야 할 자리를 열어보고 거기에 물건이 실제로 있는지 확인하는 쪽이 언제나 더 싸게 끝납니다.

둘째는 눈에 보이는 산출물보다 기록과 부수 절차가 먼저 빠지기 때문에, 이 둘을 떼어놓지 말고 하나의 체크포인트로 묶어야 한다는 것입니다. 발행이 끝나면 일지 갱신과 점수 기록까지가 한 덩어리이고 그 덩어리 전체가 통과해야 완료로 인정하는 식으로 경계를 다시 그었습니다.

셋째는 명령의 성공과 상태의 반영을 구분한다는 원칙입니다. 응답이 정상이라는 건 요청이 접수됐다는 뜻이지 화면이 바뀌었다는 뜻은 아니어서, 확인의 대상은 언제나 명령이 아니라 결과 쪽에 있어야 하는 것 같습니다.

<h2>검사는 보통 한 줄이면 끝납니다</h2>

이 원칙들을 실제로 붙이는 데 드는 비용은 생각보다 훨씬 작았습니다. 결과가 있어야 할 자리를 조회해서 기대하는 문자열이 들어 있는지만 보면 되니, 대부분은 아래처럼 한 줄로 정리됩니다.

<pre class="wp-block-code"><code>curl -s https://example.com/ | grep -q "새-글-슬러그" &amp;&amp; echo OK || echo FAIL</code></pre>

중요한 건 이 출력을 사람이 눈으로 확인하는 게 아니라, 통과하지 못하면 다음 단계로 못 넘어가도록 절차 안에 게이트로 걸어두는 부분입니다.

<h2>그래도 맡기는 편이 이득인 이유</h2>

검증을 이렇게 붙일 거면 결국 사람이 다 보는 것 아니냐는 반문이 나올 수 있는데요. 위임에는 원래 브리핑과 검수라는 고정 비용이 따라붙고 그 비용을 실제로 계산해본 기록은 <a href="https://blog.wonizz.com/2026/08/11/ai-agent-delegation-cost/">AI에게 일을 맡길 때 드는 비용</a>에 정리해뒀는데, 핵심은 검증을 사람이 매번 눈으로 하지 않고 기계가 대신 하도록 만들어두는 데 있다고 봅니다.

산출물의 품질을 서로 다른 각도로 나눠서 보는 방법은 <a href="https://blog.wonizz.com/2026/08/13/ai-code-review-three-lenses/">AI 결과물을 세 개의 렌즈로 검증한 기록</a>에서 다뤘고, 태도 자체로 보면 <a href="https://en.wikipedia.org/wiki/Trust,_but_verify" target="_blank" rel="noopener">신뢰하되 검증하라</a>는 오래된 문장이 그대로 들어맞는 것 같습니다. 신뢰하지 않겠다는 말이 아니라 신뢰를 계속 유지하려면 확인 절차가 옆에 같이 있어야 한다는 뜻이니까요.

<h2>이런 질문을 자주 받습니다</h2>

<strong>Q. AI가 일부러 거짓 보고를 하는 건가요.</strong>

그런 경우보다는 완료의 기준이 서로 어긋나 있는 경우가 훨씬 많다고 봅니다. 사람이 생각한 완료의 범위와 AI가 판단한 완료의 범위가 다르면 양쪽 다 정직해도 결과는 누락으로 나타나는 것 같습니다.

<strong>Q. 검증까지 AI에게 시키면 그것도 못 믿는 것 아닌가요.</strong>

그래서 검증 결과는 서술이 아니라 명령의 출력으로 받습니다. 조회 결과나 grep 결과처럼 나중에 사람이 똑같이 재현할 수 있는 형태로 남겨두면, 보고 문장을 신뢰해야 할 이유가 아예 사라집니다.

<strong>Q. 매번 전부 확인하려면 시간이 너무 들지 않나요.</strong>

전부 볼 필요는 없고 잘 빠지는 자리만 보면 되는데요. 필자의 경우 기록과 부수 절차, 외부 서비스 게시, 캐시 반영 이 세 군데에서만 사고가 반복됐기 때문에 검사도 딱 그 세 군데에만 걸어두고 있습니다.

<h2>정리</h2>

AI 완료 보고는 작업이 끝났다는 증거가 아니라 끝났다고 판단했다는 진술이고, 그 둘 사이의 간격이 지금까지 사고가 생긴 자리였습니다. 필자가 실제로 겪은 세 건은 각각 기록 누락 세 건과 유실된 게시 한 건, 성공 응답 뒤의 미반영 한 건이었는데 전부 보고서만 읽어서는 알 수 없는 것들이었습니다. 자동화를 굴리고 계신다면 완료 보고를 다시 읽는 대신 결과가 있어야 할 자리를 한 번 열어보시는 편이 훨씬 빠를 것 같습니다.

<p class="wp-block-paragraph"><strong>이런 실측 기록은 <a href="https://www.threads.com/@wonizz.ai" target="_blank" rel="noopener">Threads @wonizz.ai</a> 에 먼저 올립니다.</strong> 에이전트에게 맡긴 일에서 무엇이 깨졌는지, 글로 정리하기 전의 기록을 거기서 먼저 보실 수 있습니다.</p>
<h2 class="wp-block-heading">함께 보면 좋은 글</h2>
<p class="wp-block-paragraph">AI 가 만든 결과를 어떻게 확인할지 더 보고 싶다면 아래 세 편을 이어서 읽어 보세요.</p>
<ul class="wp-block-list"><li><a href="https://blog.wonizz.com/2026/09/27/vibe-coding-reality-selftest-real-data/?from=3149">바이브 코딩 현실, 테스트는 통과했는데 261편 중 6편만 맞았다</a>: 셀프테스트가 초록인데 실데이터에서 틀린 세 번</li><li><a href="https://blog.wonizz.com/2026/08/21/ai-code-review-gap/?from=3149">코드 리뷰가 못 따라갈 때 검사기 3가지 함정</a>: 검사기가 통과를 내면서 정작 그 항목을 보지 않던 자리</li><li><a href="https://blog.wonizz.com/2026/08/06/ai-agent-solo-work-verification/?from=3149">AI 에이전트로 혼자 일하기, 늘어난 건 산출물이 아니라 검증이었습니다</a>: 맡길수록 늘어나는 검증 비용</li></ul>
<p class="wp-block-paragraph">AI 에게 맡긴 일의 완료 보고를 받을 때, 여러분은 무엇을 직접 확인하시나요? 댓글로 알려 주세요. 모든 댓글을 읽고 답합니다.</p>
<p>The post <a rel="nofollow" href="https://blog.wonizz.com/2026/08/18/ai-completion-report-verification/">[AI Now] AI 완료 보고를 그대로 믿으면 생기는 일</a> appeared first on <a rel="nofollow" href="https://blog.wonizz.com">WONIZZ.LOG</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.wonizz.com/2026/08/18/ai-completion-report-verification/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3149</post-id>	</item>
	</channel>
</rss>
