frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

BoxLite Love AI agent – SQLite for VMs: embeddable AI agent sandboxing

https://github.com/boxlite-labs/boxlite
1•dorianzheng•1h ago

Comments

dorianzheng•1h ago

  The problem:

  AI agents are most useful when they have freedom—freedom to write code, install packages, run scripts, explore solutions. But that freedom is dangerous. One hallucinated rm -rf / or a malicious package install, and your host system pays the price.

  So we restrict them. Limit file access. Disable network. Whitelist commands. The agent becomes safer but also dumber—unable to iterate, experiment, or recover from mistakes like a human developer would.

  I wanted to give AI agents a full computer they could break without breaking mine.

  Why not existing tools?

  When I started sandboxing AI-generated code, nothing quite fit:

  - Docker shares the host kernel—container escapes are a real attack surface, and that makes me nervous
  - QEMU/libvirt is powerful but heavyweight—XML configs, daemon processes, steep learning curve
  - Cloud sandboxes (E2B, Modal, etc.) work, but you're locked into their platform with limited customization
  - Kata Containers is designed for Kubernetes orchestration, not for embedding in a Python script

  The SQLite idea:

  I've been thinking about why SQLite works so well. Before SQLite, databases meant running a server—PostgreSQL, MySQL, managing daemons, configuring connections. SQLite asked: what if it was just a library? No server. Just import sqlite3.

  I wanted the same thing for VMs.

  So I started building BoxLite—an attempt to make VMs embeddable like SQLite. A library call that gives you a real micro-VM with its own kernel. No daemon. No root.

  import asyncio
  import boxlite

  async def main():
      async with boxlite.SimpleBox(image="python:slim") as box:
          result = await box.exec("python", "-c", "print('Hello from VM!')")
          print(result.stdout)

  asyncio.run(main())

  To be clear: this is early.

  It works on macOS Apple Silicon and Linux. You can pull OCI images, mount volumes, forward ports. There are some higher-level abstractions (BrowserBox for Playwright, ComputerBox for desktop automation).

  But there are bugs. Boot time is 200ms for hot runs (I want it under 100ms). Documentation is thin. Error messages could be better. macOS Intel and Windows aren't supported. I haven't battle-tested it at scale.

  I'm sharing it now because I'd rather build this with feedback than in isolation.

  What I'd love to hear:
  - Does the SQLite-for-VMs idea make sense, or am I stretching the analogy?
  - What would you actually use this for?
  - What's broken or confusing when you try it?

  GitHub: https://github.com/boxlite-labs/boxlite
  PyPI: https://pypi.org/project/boxlite/

Marco Rubio: No more woke fonts

https://www.theatlantic.com/newsletters/2025/12/marco-rubio-woke-font-calibri/685212/
2•atakan_gurkan•6m ago•0 comments

Democratic states sue Trump administration over new $100k fee for H-1B visas

https://www.cnn.com/2025/12/12/politics/h-1b-visa-fee-lawsuit
1•Beijinger•6m ago•0 comments

Writing a Type-Safe Linux Perf Interface in Zig

https://pyk.sh/blog/2025-12-11-type-safe-linux-perf-event-open-in-zig
1•peeyek•7m ago•0 comments

Google and Apple roll out emergency security updates after zero-day attacks

https://techcrunch.com/2025/12/12/google-and-apple-roll-out-emergency-security-updates-after-zero...
1•colanderman•8m ago•0 comments

Unitree Debuts the First Humanoid Robot "App Store"

https://twitter.com/UnitreeRobotics/status/1999712278204285361
2•elfbargpt•9m ago•0 comments

Show HN: Browser4 – an open-source browser engine for agents and concurrency

https://github.com/platonai/Browser4
1•galaxyeye•10m ago•0 comments

How Long Does It Take to Merge a PR into VSCode?

https://joseph-xiao.notion.site/How-Long-Does-It-Take-to-Merge-a-PR-into-VSCode-2c824be1b42e80e48...
1•jxiao32•16m ago•1 comments

MongoKV – Tiny async/sync key–value store on top of MongoDB

https://harrisonerd.com/mongokv/
1•harrisonerd•16m ago•1 comments

Cybercriminals are exploiting ChatGPT and Grok to spread AMOS malware to Macs

https://techoreon.com/cybercriminals-exploit-chatgpt-grok-amos-malware-macos/
4•ashishgupta2209•23m ago•0 comments

SpaceX Valued at $800B, as It Prepares to Go Public

https://www.nytimes.com/2025/12/12/technology/elon-musk-spacex-ipo.html
1•hockeyface•27m ago•0 comments

Doxers Posing as Cops Are Tricking Big Tech Firms into Sharing People's Data

https://www.wired.com/story/doxers-posing-as-cops-are-tricking-big-tech-firms-into-sharing-people...
11•iamnothere•29m ago•2 comments

Apples

https://xkcd.com/3180/
1•baruchel•30m ago•0 comments

Contra four-wheeled suitcases, sort of (2023)

https://dynomight.net/luggage/
1•Ariarule•32m ago•1 comments

Recovering Anthony Bourdain's (really) lost Li.st's

https://sandyuraz.com/blogs/bourdain/
1•gregsadetsky•32m ago•0 comments

Scientists Uncover Key Driver of Treatment-Resistant Cancer

https://today.ucsd.edu/story/scientists-uncover-key-driver-of-treatment-resistant-cancer
3•gmays•38m ago•0 comments

Apple has locked my Apple ID, and I have no recourse. A plea for help

https://hey.paris/posts/appleid/
31•parisidau•40m ago•6 comments

The Invitation-Only Stock Market for the Wealthy

https://www.wsj.com/finance/investing/private-stock-market-growth-bb71bde1
2•mudil•43m ago•2 comments

Free software grows as a function of social utility (2022)

https://ariadne.space/2022/08/05/free-software-grows-as-a.html
1•ghssds•45m ago•0 comments

Configure automatic detection of work location in Microsoft Teams

https://learn.microsoft.com/en-us/microsoft-365/places/configure-auto-detect-work-location
1•TheDataMaverick•1h ago•0 comments

The Coupang data breach that hit two-thirds of South Korea

https://www.ft.com/content/df4042fa-3e56-410f-b905-4aed8fd434ac
1•zdw•1h ago•1 comments

Poor Johnny still won't encrypt

https://bfswa.substack.com/p/poor-johnny-still-wont-encrypt
13•zdw•1h ago•10 comments

Show HN: Flowctl – Self-service workflows with approvals and SSO. Single Binary

https://github.com/cvhariharan/flowctl
3•cv_h•1h ago•0 comments

New Google web ecosystem tools and partnerships

https://blog.google/products/search/tools-partnerships-web-ecosystem/
1•gmays•1h ago•0 comments

Show HN: OAuth-style authorization for AI agents

https://www.npmjs.com/package/@variant96/pia-sdk
2•Pukuta•1h ago•0 comments

Show HN: Ten Principles of Good Design

https://tonygaeta.com/labs/ten-principles-of-good-design
2•LightMorpheus•1h ago•0 comments

Coding Agents and Complexity Budgets

https://leerob.com/agents
2•tortilla•1h ago•0 comments

Physicians AI Report

https://2025-physicians-ai-report.offcall.com/
1•samuel246•1h ago•0 comments

Model Context Protocol (MCP) Support for Google Services

https://cloud.google.com/blog/products/ai-machine-learning/announcing-official-mcp-support-for-go...
1•manveerc•1h ago•0 comments

Show HN: Tandem – Real-time collaborative editor with AI attribution tracking

https://github.com/lmanchu/tandem/tree/v3
2•Lmanchu•1h ago•1 comments

UK developing urgent plan for conflict, minister says

https://ukdefencejournal.org.uk/uk-developing-urgent-plan-for-conflict-minister-says/
3•Bender•1h ago•0 comments