frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: We told OpenClaw to rm -RF and it failed successfully

https://securetrajectories.substack.com/p/openclaw-rm-rf-policy-as-code
1•joshdevon•1h ago
As we all know, OpenClaw is awesome precisely because it gives us Simon Willison’s lethal trifecta: Access to private data, exposure to untrusted content, and the ability to externally communicate.

While extremely risky, it gives us a glimpse of the future we can have if we actually could trust agents.

To date, sandboxing (or buying mac-minis) has been the approach to reducing risk. While necessary, sandboxes also make the agent less useful because they ultimately contain and restrict the agent's helpful capabilities.

To wrangle OpenClaw, we took a complementary approach. Instead of just a perimeter, we built an open source OpenClaw extension that creates deterministic lanes for the agent using Cedar (AWS's policy as code language).

For example, we created a policy that forbids OpenClaw from using rm. We aren't trying to stop the LLM from thinking about deleting a file or stop it from being prompt injected to delete a file. Instead, the extension catches the tool call and blocks it before execution.

We are shipping with 3 policy packs (103 rules):

-Baseline pack: Protections for sudo, rm, credentials, etc.

-OpenClaw System Protection: Protects SOUL.md, identity files, etc.

-OWASP Agentic Pack: Based on the OWASP Top 10 for Agentic Applications.

Just like OpenClaw, this is experimental and hasn't been rigorously tested, so please don't use the extension to protect anything valuable or sensitive. We hope this project is a strong proof of concept for how we can put agents in risky situations and still trust them with deterministic rules.

For more details and the link to the repo, please check out our write-up. Would love to hear what others think of the approach and what policies you think would be useful to add.

Lessons learned building a Node.js malware scanner to 400 stars (Open Source)

1•alrjoe•55s ago•0 comments

Attention Sinks and Compression Valleys in LLMs

https://arxiv.org/abs/2510.06477
1•alexkranias•1m ago•0 comments

Part 2 - AI Chat Evaluation of the Formal Language in He Xin's PEPC System

1•nikicsy•2m ago•0 comments

Hand tool rewrites ancient Egyptian history

https://www.popsci.com/science/ancient-egypt-hand-tool/
1•delichon•2m ago•0 comments

A note about personal security

https://werd.io/a-note-abo/
1•sdoering•3m ago•0 comments

AI Chat Evaluation of the Formal Language in He Xin's PEPC System

1•nikicsy•3m ago•0 comments

A Note on File History in Emacs

https://brainbaking.com/post/2026/02/a-note-on-file-history-in-emacs/
1•Brajeshwar•3m ago•0 comments

Revisionist History – Aliens, Secrets and Conspiracies

https://steveblank.com/2026/02/10/revisionist-history-aliens-secrets-and-conspiracies/
1•Brajeshwar•3m ago•0 comments

Show HN: cbt (C++ Build Tool)

https://github.com/swar-mukh/cbt
1•swar-mukh•3m ago•0 comments

Open model StepFun-3.5 is #1 on MathArena, an uncheatable math benchmark

https://twitter.com/CyouSakura/status/2021511358626554322
1•diyer22•3m ago•0 comments

Show HN: Bitcoin, GEB, and Bach's fugues share the same structural move

https://falsework.dev/
1•falsework•4m ago•0 comments

Functional Programming in M4

https://minnie.tuhs.org/pipermail/tuhs/2020-August/022108.html
1•fanf2•5m ago•0 comments

AI makes it easier to build the wrong thing faster

https://newsletter.masilotti.com/p/ai-makes-it-easier-to-build-the-wrong
1•joemasilotti•5m ago•1 comments

Show HN: I built a macOS desktop toy that patrols while you work

https://airwolfspace.com/tinytanks
1•kailuo•6m ago•0 comments

Poison at Play: Unsafe lead levels found in half of New Orleans playgrounds

https://veritenews.org/2026/02/05/poison-at-play-playgrounds-lead-levels/
1•hn_acker•6m ago•0 comments

Unresponsive Buttons on My Fastest Hardware

https://blog.jim-nielsen.com/2026/unresponsive-buttons/
2•speckx•6m ago•0 comments

AI-First Company Memos

https://the-ai-native.company/
1•bobismyuncle•6m ago•0 comments

How to Test ProxySQL Read/Write Split with Sysbench

https://rendiment.io/mysql/proxysql/2026/02/03/sysbench-proxysql.html
1•nethalo•7m ago•0 comments

The singularity won't be gentle – by Nate Silver

https://www.natesilver.net/p/the-singularity-wont-be-gentle
2•rbanffy•8m ago•0 comments

A New Computer Could Replace Electricity with Light

https://www.popularmechanics.com/science/a70223544/computer-could-replace-electricity-with-light/
1•falcor84•9m ago•0 comments

Show HN: Health.md - Apple Health → Markdown

https://healthmd.isolated.tech/
1•codybontecou•9m ago•0 comments

PicoClaw: Ultra-Efficient AI Assistant in Go

https://github.com/sipeed/picoclaw
1•wicket•10m ago•0 comments

AITools.coffee – GitHub metrics observatory tracking 27K+ open-source AI repos

https://aitools.coffee
1•alexela84•10m ago•1 comments

AI Agents 101: From Concept to Code (No Frameworks Required)

https://medium.com/@kamil.tustanowski/ai-agents-101-from-concept-to-code-no-frameworks-required-2...
1•semerkchet•10m ago•0 comments

Databases should contain their own Metadata – Use SQL Everywhere

https://floedb.ai/blog/databases-should-contain-their-own-metadata-instrumentation-in-floe
4•matheusalmeida•11m ago•0 comments

Seeking Order in Chaos

https://garrit.xyz/posts/2026-02-11-on-seeking-order-in-chaos
3•garritfra•11m ago•0 comments

Show HN: Funxy – A typed scripting language that embeds into Go apps

https://github.com/funvibe/funxy
2•funbitty•11m ago•0 comments

The jarring experience of developing today

https://its.beer/thoughts/the-jarring-experience-of-developing-today
1•beerd•12m ago•0 comments

Kiro: DeepSeek, MiniMax, and Qwen now available as open weight model options

https://kiro.dev/changelog/models/deepseek-minimax-and-qwen-now-available-as-open-weight-model-op...
2•siegers•12m ago•0 comments

Terence Tao: Why I Co-Founded SAIR

https://www.youtube.com/watch?v=Z5GKnb4H_bM
1•nyc111•14m ago•0 comments