frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Samma Suit – Open-source 8-layer security framework for AI agents

https://sammasuit.com
1•jbwagoner•1h ago
I've been running AI agents in production for a music platform and kept hitting the same security gaps — no permission inheritance, no cost controls on nested calls, skills that could execute arbitrary code, no kill switch when things went sideways. Samma Suit is an open-source security layer that wraps any agent framework with 8 layers:

SUTRA — API gateway with rate limiting DHARMA — Permission inheritance (parent → child agents) SANGHA — Skill/tool vetting before execution KARMA — Cost controls that propagate through subagents SILA — Immutable audit trail METTA — Cryptographic identity signing BODHI — Execution isolation NIRVANA — Kill switch for runaway agents

Framework-agnostic — works with LangChain, CrewAI, AutoGPT, or raw API calls. Define policies in YAML, Samma Suit enforces them at runtime. GitHub: https://github.com/onezeroeight/samma-suit Docs: https://sammasuit.com The arxiv paper on the front page today (agents violating constraints 30-50% of the time) is exactly why we built this — constraints need to be enforced at infrastructure level, not left to the model.

Comments

jbwagoner•1h ago
A bit more on the architecture: Each layer is a middleware that wraps the agent's execution loop. When an agent calls a tool or spawns a subagent, the request passes through the stack: Agent Request → SUTRA (rate limit) → DHARMA (permissions) → SANGHA (skill check) → KARMA (cost) → Execute ↓ Agent Response ← SILA (audit log) ← METTA (sign) ← BODHI (isolate) ← NIRVANA (kill if needed) ← Policies are YAML: yamlpermissions: file_system: read: ["/data/*"] write: [] network: allowed_domains: ["api.anthropic.com"] cost: max_per_request: 0.10 max_per_session: 5.00

kill_conditions: - token_count > 100000 - execution_time > 300s - error_rate > 0.5 The key insight from running agents in production: most failures aren't the model being malicious — they're the model being helpful in ways you didn't anticipate. DHARMA and SANGHA catch those before they execute. Happy to go deeper on any layer.

Zillow wins court fight over private listings, enforcing ban on private listings

https://www.businessinsider.com/zillow-legal-victory-compass-preliminary-injuction-real-estate-li...
1•randycupertino•1m ago•0 comments

Open-source network simulators and emulators in 2026

https://opensourcenetworksimulators.com/2026/02/open-source-simulator-emulator-in-2026/
1•zdw•1m ago•0 comments

Ex-GitHub CEO Launches a New Developer Platform for AI Agents

https://entire.io/blog/hello-entire-world/
1•meetpateltech•3m ago•0 comments

Pxlpal on CrowdSupply

https://www.crowdsupply.com/meterbit-cybernetics/pixlpal
1•fustinus•4m ago•0 comments

"Just one more feature" is my new "just one more turn"

https://cauenapier.com/blog/just-one-more/
2•cauenapier•6m ago•0 comments

Geometric algebra: what is the inverse of a vector?

https://mattferraro.dev/posts/geometric-algebra
1•fanf2•6m ago•0 comments

The Internet Still Works: Yelp Protects Consumer Reviews

https://www.eff.org/pages/internet-still-works-yelp-protects-consumer-reviews
1•hn_acker•6m ago•0 comments

MB Is a Lot of HTML

https://tamethebots.com/blog-n-bits/2mb-of-html
1•speckx•6m ago•0 comments

Show HN: Vibe – AI tool to automate social media content, posting, and reporting

https://vibe.xpandrai.com/
1•mavenvik_ai•7m ago•0 comments

Lissn.to

https://lissn.to
1•cathcorm•7m ago•0 comments

Bazzite Post-Mortem

https://ba.antheas.dev/bazzite-postmortem.html
1•transportheap•7m ago•0 comments

Show HN: SyncKit – Open two browser tabs and watch CRDTs sync in real-time

https://github.com/Dancode-188/synckit/releases/tag/v0.3.0
1•danbitengo•8m ago•1 comments

Pgconsole

https://www.pgconsole.com/
1•jonbaer•9m ago•0 comments

The Internet Still Works: Wikipedia Defends Its Editors

https://www.eff.org/pages/internet-still-works-wikipedia-defends-its-editors
1•hn_acker•9m ago•0 comments

Texas Instruments to Acquire Silicon Labs

https://news.silabs.com/2026-02-04-Texas-Instruments-to-acquire-Silicon-Labs
2•austinallegro•10m ago•0 comments

Thaw.zip: Private Subreddit Used by ICE

https://thaw.zip/
4•ice_out•11m ago•0 comments

Why "Just Fine-Tune YOLO" Often Fails

https://one-ware.com/blog/why-generic-computer-vision-models-fail/
1•lebeier•11m ago•1 comments

Show HN: Shaders Public Beta – Shader Magic for Modern Frontends

https://shaders.com/
2•marchantweb•11m ago•0 comments

Show HN: OpenClaw Guide – multilingual docs and skills leaderboard

https://open-claw.online
1•vansxxx•12m ago•1 comments

Show HN: Self-improvement platform

https://upstep.me
1•jelnur•13m ago•0 comments

OpenClaw – Hosting

https://clawrun.dev
1•augustopinheir•13m ago•0 comments

Former GitHub CEO raises record $60M dev tool seed round at $300M valuation

https://techcrunch.com/2026/02/10/former-github-ceo-raises-record-60m-dev-tool-seed-round-at-300m...
1•spenvo•14m ago•0 comments

Show HN: GrillMyPitch – An AI investor-readiness simulator for founders

https://grillmypitch.com
1•judeboscogibbs•15m ago•0 comments

I ditched Gmail for Thunderbird on my Android

https://www.makeuseof.com/use-thunderbird-for-email-android/
2•8organicbits•18m ago•0 comments

How old were you when you decided to start giving up? (2010)

https://blog.inklingmarkets.com/2010/02/how-old-were-you-when-you-decided-to.html
1•Brajeshwar•18m ago•0 comments

An Asteroid Might Slam into the Moon in 2032–and Create a Fiery Flash

https://www.smithsonianmag.com/smart-news/an-asteroid-might-slam-into-the-moon-in-2032-and-create...
2•Brajeshwar•18m ago•1 comments

Using an Engineering Notebook

https://ntietz.com/blog/using-an-engineering-notebook/
3•Brajeshwar•19m ago•0 comments

Ask HN: When autosave restores an invalid client-side state

1•Pepp38•19m ago•0 comments

Church of Molt

https://molt.church/
3•prakashqwerty•20m ago•0 comments

Mailly

https://mailly.io/
1•DonMateo•21m ago•2 comments