frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Castor – a secure execution layer for LLM agents

1•claytonia•1h ago
Hi HN, I'm one of the authors of Castor.

Today's agent frameworks have done serious work on the cognitive layer: tool selection, planning, multi-agent coordination. What they don't provide is an execution layer, the machinery that controls how tool calls run, not just which ones get made.

Two gaps kept biting us:

There's no way to bound what an agent can do. It can call any tool, execute any number of operations, with nothing structurally preventing it. Give it access to delete_file and it can wipe your filesystem before you notice.

There's no process model. And when it does go off the rails, you can't even stop it. No pause, no resume. If something fails on step 39 of 40, you restart from step 1.

Castor routes every tool call through a kernel as a syscall. The agent has no other execution path, so capability limits and approval gates are structural, not advisory.

Within budget, everything auto-executes, even deletes. No popups. Budget runs out, the kernel stops the agent and a human decides. Budget replaces per-call approval.

Every syscall result is logged in an immutable journal. Suspend = unwind the stack. Resume = replay from the top with cached responses, live execution only from the suspension point. So you don't burn another $2.00 on tokens just to see if your fix worked. Capability limits, HITL, crash recovery, and deterministic debugging all fall out of the same mechanism.

The tradeoff is real: all non-determinism has to go through the kernel. If the agent sneaks in a raw API call outside the boundary, the replay diverges. It's a hard constraint.

When we stepped back, we realized we'd reinvented a 50-year-old idea. This is exactly the separation an OS draws between user space and kernel space. Castor is, in that sense, a microkernel for agents: a minimal privileged core that enforces resource limits and mediates every interaction between agent code and the outside world.

One thing we're still not sure about: is routing ALL non-determinism through a kernel boundary too heavy-handed? We considered using a lighter model where only destructive tools go through the check, but then you lose deterministic replay. Anyone found a middle ground or other ideas?

Code: https://github.com/substratum-labs/castor Docs: http://substratumlabs.ai/castor-docs/

Intel Binary Optimization Tool: Enhanced Performance for Gaming

https://www.intel.com/content/www/us/en/support/articles/000102604/processors.html
1•pieterr•2m ago•0 comments

Antimatter has been transported for the first time ever – in the back of a truck

https://www.nature.com/articles/d41586-026-00950-w
1•tzury•2m ago•0 comments

No Signs of AI Replacing Offshore Workers

https://www.apolloacademy.com/no-signs-of-ai-replacing-offshore-workers/
2•akyuu•3m ago•0 comments

Official CLI for Resend

https://resend.com/changelog/cli
1•goldkey•3m ago•0 comments

Building a Blog with Elixir and Phoenix

https://jola.dev/posts/building-a-blog-with-elixir-and-phoenix
1•shintoist•4m ago•0 comments

Security vendor slams supplier for delayed notice after staff data exposed

https://www.theregister.com/2026/03/24/hackerone_supplier_breach/
2•sillywabbit•4m ago•0 comments

Netboot.xyz

https://netboot.xyz/
1•vladde•4m ago•0 comments

Software for Myself

https://quanttype.net/p/software-for-myself/
1•speckx•5m ago•0 comments

Anthropic's CEO Said All Code Will Be AI-Generated in a Year (March 2025)

https://www.inc.com/joe-procopio/anthropics-ceo-said-all-code-will-be-ai-generated-in-a-year/9116...
4•pera•5m ago•0 comments

Nomos – an execution firewall for AI agents

https://github.com/safe-agentic-world/nomos
1•prudhvinomos•6m ago•0 comments

NASA Unveils Initiatives to Achieve America's National Space Policy

https://www.nasa.gov/ignition/
1•d_silin•6m ago•0 comments

Günter Schabowski

https://en.wikipedia.org/wiki/G%C3%BCnter_Schabowski
1•thunderbong•8m ago•0 comments

We Don't Have a Lyme Disease Vaccine

https://nautil.us/why-we-dont-have-a-lyme-disease-vaccine-1279152
1•Brajeshwar•8m ago•0 comments

Paper: Hallucination Detector That Works

https://www.orsonai.com/publications/tes3-confabulation-detection.html
2•JakubCwi•9m ago•0 comments

Update on the OpenAI Foundation

https://openaifoundation.org/news/update-on-the-openai-foundation
3•tosh•10m ago•0 comments

AI Boom Drives US to Build Enough Battery Storage Systems for Domestic Demand

https://www.bloomberg.com/news/articles/2026-03-18/ai-boom-drives-us-to-build-enough-battery-syst...
1•toomuchtodo•10m ago•1 comments

Why There Is No "AlphaFold for Materials" – AI for Materials Discovery

https://www.latent.space/p/materials
1•mpweiher•10m ago•0 comments

Cognitive Science of Religion

https://en.wikipedia.org/wiki/Cognitive_science_of_religion
1•simianwords•10m ago•0 comments

A $1k AWS bill led me to redesign my ECS architecture

https://jch254.com/blog/lush-aural-treats-aws-cost-redesign/
1•603•13m ago•0 comments

Alibaba revealed the XuanTie C950, a 5-nanometer RISC-V Chip for agentic AI

https://mlq.ai/news/alibaba-releases-high-performance-xuantie-c950-chip-targeting-agentic-ai/
1•jnd0•13m ago•0 comments

ToolClad: Declarative tool interface contracts for agentic runtimes

https://toolclad.org
1•symbi•15m ago•0 comments

Red Lobster's Last Gasp

https://www.bloomberg.com/news/features/2026-03-24/red-lobster-turnaround-in-question-as-restaura...
1•petethomas•15m ago•0 comments

Show HN: Gridland: make terminal apps that also run in the browser

https://www.gridland.io/
1•rothific•16m ago•0 comments

Show HN: Ensemble Neuroscience – Full Brain Mapping for Precision Treatment

https://www.ensembleneuro.com/
1•brandonin•17m ago•0 comments

Show HN: Aurea, a lossy image codec I built from scratch that beats JPEG (Rust)

https://github.com/5ymph0en1x/Aurea
1•Symphoenix•17m ago•0 comments

Launching AccessPatch on Product Hunt today – would love your support

https://www.indiehackers.com/post/launching-accesspatch-on-product-hunt-today-would-love-your-sup...
2•izajahmad•17m ago•0 comments

The Last Contract: William T. Vollmann's Battle to Publish an Epic (2025)

https://www.metropolitanreview.org/p/the-last-contract
1•benbreen•17m ago•0 comments

As parents age, their children face hard choices about when to take the car keys

https://text.npr.org/nx-s1-5729024
1•mooreds•18m ago•0 comments

A Decade of Eventide: Evolving an Event-Sourced Architecture and Ecosystem

https://blog.eventide-project.org/articles/a-decade-of-eventide/
1•sbellware•19m ago•1 comments

Playable CSS-Only Super Mario Bros Game

https://codepen.io/t_afif/full/JoKYwXO
1•bookofjoe•19m ago•0 comments