frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Secure Agent Starter – A minimal template for building safer AI agents

https://github.com/timbuctoo/secure-agent-starter
2•timbucto2•1h ago
I’ve been exploring how to make AI agents safer to use in real applications, especially as they start interacting with tools, APIs, and real systems. One recurring problem is that agents can hallucinate actions, call tools they shouldn’t, or over‑reach in ways that make them hard to trust in production.

To experiment with better patterns, I put together a small starter repo: Secure Agent Starter https://github.com/timbuctoo/secure-agent-starter

It’s intentionally minimal — not a full SDK — but it demonstrates a simple structure for: - Capability‑based permissions - An “action firewall” pattern - Example capability + policy files - A tiny agent example - A mock authorization step (no backend required) - A folder layout you can drop into any agent project

The goal is to give developers a mental model for agent security before wiring up real tools or APIs. Think of it as a conceptual starting point for designing safer agent architectures.

I’d love feedback on: - What security patterns you’d want to see next - Whether this structure makes sense for real‑world agent projects - Any missing pieces that would make this more useful

Thanks for taking a look.

Comments

timbucto2•1h ago
Thanks for checking this out. A quick note: this repo is intentionally lightweight. It’s not trying to be a framework — just a starting point for thinking about agent security in a more structured way.

The next steps I’m considering: - Adding a real capability‑token validator - A more complete “action firewall” example - A Python version - A few real‑world tool integrations (email, DB, file ops) - A diagram of how this fits into an agent stack

If you have thoughts on what would be most valuable, I’d love to hear them.

timbucto2•1h ago
A lot of agent frameworks focus on reasoning, planning, or tool orchestration — but very few focus on security boundaries. Right now, most agents can call any tool they’re given, and the only guardrail is “hope the model behaves.”

This repo is an attempt to explore a different pattern: - Agents request actions - A separate layer authorizes or denies them - Capabilities are explicit, not implicit - Policies are external, not baked into prompts

Even a simple mock version helps clarify the architecture. My goal is to make this pattern easier to adopt before agents start touching real systems.

With Neo, Apple Goes After Windows 11

https://om.co/2026/03/04/apple-goes-after-window-11-with-neo/
1•tosh•57s ago•0 comments

Show HN: SpacePill – Better macOS Space Context Switching

1•jakequist•1m ago•0 comments

Show HN: I built a prediction market that predicts itself

https://www.follymarket.com
1•pkundr•2m ago•0 comments

The Next Version of Curling IO

https://curling.io/blog/the-next-version-of-curling-io
1•PaulHoule•3m ago•0 comments

Fast IP and GPS to Location API (50ms, Global, 99.9% Uptime)

https://www.jeleo.zone.id/
1•wtronk•4m ago•1 comments

"Personal Data": more than a definition, a quasi-constitutional stake in EU

https://www.europeanlawblog.eu/pub/yc0l0slk/release/1
1•fanf2•4m ago•0 comments

IMB Piracy and Armed Robbery Map 2025

https://icc-ccs.org/2025-2/
1•michaefe•5m ago•0 comments

New Emoji: Distorted Face

https://jenniferdaniel.substack.com/p/new-emoji-distorted-face
1•ChrisArchitect•5m ago•0 comments

This job has become the ultimate case study why AI won't replace human workers

https://www.cnn.com/2026/02/09/tech/ai-replacing-jobs-concerns-radiology
1•mhb•6m ago•0 comments

Learnings from a No-Code Lib: Keep the Spec Driven Development Triangle in Sync

https://www.dbreunig.com/2026/03/04/the-spec-driven-development-triangle.html
1•dbreunig•7m ago•0 comments

Show HN: I made Claude Code block my distractions and track everything I ship

https://twitter.com/daxaur/status/2029258604084158559
1•daxaur•8m ago•1 comments

My MCP Server Setup: A Practical Guide to Wiring AI into Everything

https://crunchtools.com/my-mcp-server-setup-practical-guide/
1•abdelhousni•8m ago•0 comments

Man Arrested for Plotting with Others to Murder or Kidnap Two Dissidents Abroad

https://www.justice.gov/usao-sdny/pr/man-arrested-plotting-others-murder-or-kidnap-two-victims-ab...
1•737min•8m ago•0 comments

Does Altman Deserve the Heat?

https://tapestry.news/tech/altman-heat/
1•sonalidee•8m ago•1 comments

Harjus v4 adds kernel bypass and more

https://shufflingbytes.com/posts/harjus-release-4.0.0/
1•ValtteriL•9m ago•0 comments

Show HN: TerminalNexus – Turn CLI commands into reusable buttons (Windows)

1•danhof_sss•9m ago•0 comments

Why Autonomous Agents Failed the Initial Hype: An AutoGen Retrospective

https://www.youtube.com/watch?v=2cnxea3xkzM
1•alexchaomander•9m ago•1 comments

Rob Grant Obituary on Ganymede and Titan

https://www.ganymede.tv/2026/03/obituary-rob-grant/
1•nephihaha•10m ago•1 comments

Agent-experience: visual reference to patterns, surfaces, and infrastructure

https://github.com/ygwyg/agent-experience
1•simonpure•10m ago•0 comments

C++ Reflection: Another Monad

https://www.elbeno.com/blog/?p=1813
1•ingve•11m ago•0 comments

Invoicesio.app – Invoice and billing for freelancers and small businesses

https://invoicesio.app/
1•dimitrisal•12m ago•1 comments

AWS-hosted tech providers urge Middle East customers to fail over now

https://www.theregister.com/2026/03/04/aws_saas_middle_east_customer_warnings/
2•Bender•12m ago•0 comments

Dev stunned by $82K Gemini bill after unknown API key thief goes to town

https://www.theregister.com/2026/03/03/gemini_api_key_82314_dollar_charge/
1•Bender•12m ago•1 comments

Faster C software with Dynamic Feature Detection

https://gist.github.com/jjl/d998164191af59a594500687a679b98d
2•todsacerdoti•13m ago•0 comments

Get Paid for Good Posts

https://treechat.com/
3•mitya777•14m ago•0 comments

Up to 10% of Firefox crashes are due to bad memory [thread]

https://mas.to/@gabrielesvelto/116171753263415921
1•MBCook•14m ago•0 comments

With developer verification, Google's Apple envy threatens Android's open legacy

https://arstechnica.com/gadgets/2026/03/with-developer-verification-googles-apple-envy-threatens-...
1•Bender•14m ago•0 comments

Ask HN: Does Claude Code's abilities fluctuate for you too?

1•ammerfest•14m ago•0 comments

CodeRabbit tops the F1 score in Martian's code review benchmarks

https://www.coderabbit.ai/blog/coderabbit-tops-martian-code-review-benchmark
1•smb06•16m ago•0 comments

Open Source Iran War Cost Tracker: 45.7B

https://iranwarcost.com
11•koverda•16m ago•1 comments