frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Agent sandboxing tools that mount projects R/W have gaping exploits

3•rsyring•1h ago
I've been reviewing Agent sandboxing solutions recently and it occurred to me there is a gaping vector for persistent exploits for tools that let the agent write to the project directory.

I had originally thought this would ok as we could review everything in the git diff. But, it later occurred to me that there are all kinds of files that the agent could write to that I'd end up executing, as the developer, outside the sandbox. Every .pyc file for instance, files in .venv , .git hook files.

ChatGPT[1] confirms the underlying exploit vectors and also that there isn't much discussion of them in the context of agent sandboxing tools.

My conclusion from that is the only truly safe sandboxing technique would be one that transfers files from the sandbox to the dev's machine through some kind of git patch or similar. I.e. the file can only transfer if it's in version control and, therefore presumably, has been reviewed by the dev before transfer outside the sandbox.

Thoughts or recommendations?

1: https://chatgpt.com/share/69c3ec10-0e40-832a-b905-31736d8a3438

Crypto donations to UK parties to be banned

https://www.bbc.co.uk/news/articles/c5y8d2qvr9do
1•astoor•36s ago•0 comments

Show HN: Sudo for AI agents – cryptographic delegation instead of API keys

https://github.com/kanoniv/auth-action
1•dreynow•50s ago•0 comments

Block the LiteLLM supply chain attack, with Nono.sh runtime Security

https://nono.sh/blog/nono-litellm
1•decodebytes•1m ago•0 comments

One man used 10k bots to steal $8M from music artists

https://www.bitdefender.com/en-us/blog/hotforsecurity/10k-bots-steal-8-million-from-music-artists
1•speckx•2m ago•0 comments

Safely evolve your JSON schemas. Check backward/forward compatibility

https://jsoncompat.com/
1•pranay01•3m ago•0 comments

Show HN: As Notes – A Static Site Generator in Your Markdown Knowledgebase

https://blog.asnotes.io/as-notes-a-static-site-generator-in-your-markdown-knowledgebase
4•gbro3n•3m ago•0 comments

Wikipedia has banned AI-generated text, with two exceptions

https://www.howtogeek.com/wikipedia-banned-ai-generated-text-in-articles-with-two-exceptions/
1•l5870uoo9y•4m ago•0 comments

AI Agent action safety is not covered yet

1•praneeth-v•4m ago•0 comments

Debunking Classical Pseudo-Paradoxes of Logic

1•kokhanserhii•8m ago•1 comments

Orbital data centers, part 1: There's no way this is economically viable, right?

https://arstechnica.com/space/2026/03/orbital-data-centers-part-1-theres-no-way-this-is-economica...
1•rbanffy•8m ago•0 comments

A Brief History of San Francisco's Middle School Algebra Mess

https://www.educationprogress.org/p/a-brief-history-of-san-franciscos
1•geox•9m ago•0 comments

Ancient Grapes Reveal Long History of Modern Wines

https://www.nytimes.com/2026/03/24/science/ancient-grapes-dna-winemaking.html
1•Brajeshwar•9m ago•0 comments

Can It Resolve Doom? Game Engine in 2k DNS Records

https://blog.rice.is/post/doom-over-dns/
1•birdculture•9m ago•0 comments

There Really Was a 'Mississippi Miracle' in Reading. States Should Learn from It

https://www.the74million.org/article/there-really-was-a-mississippi-miracle-in-reading-states-sho...
2•jyunwai•10m ago•0 comments

Apple App Store Is Flooded with AI Slop and Legitimate Developers Are Paying

https://www.forbes.com/sites/josipamajic/2026/03/24/the-apple-app-store-is-flooded-with-ai-slop-a...
2•htk•11m ago•1 comments

Ban Pay-to-Play National Security Approvals

https://www.lawfaremedia.org/article/ban-pay-to-play-national-security-approvals
1•hn_acker•11m ago•0 comments

Any idea for my new feature? HTTPS://portolabs.id

1•grymore•11m ago•0 comments

White House Takes Aim at Biased AI in Government, Leaves Key Gaps

https://www.lawfaremedia.org/article/white-house-takes-aim-at-biased-ai-in-government--leaves-key...
1•hn_acker•12m ago•0 comments

Show HN: Multi-step form component for Framer with a JSON-driven wizard

https://alxdsn.fr/quiet-form/
1•adesane•12m ago•0 comments

Open-source OWASP security testing for AI models and agents

https://github.com/tessera-ops/tessera
1•alysheaib•13m ago•1 comments

Show HN: HowMuchGameHeroesMake

https://howmuchgameheroesmake.vercel.app/
1•leonagano•14m ago•0 comments

I Tried to Invent a Better Replication Policy. It Failed

https://halil.cetiner.me/nearsight/
1•bayneri•15m ago•0 comments

A Eulogy for Vim

https://drewdevault.com/2026/03/25/2026-03-25-Forking-vim.html
13•mtts•16m ago•0 comments

TeamMind – persistent memory for Claude Code (no API key, runs locally)

https://github.com/natedemoss/Teammind
1•natedemoss•16m ago•0 comments

The Cost of Doing Business

https://pluralistic.net/2026/03/25/fact-intensive/
1•hn_acker•17m ago•0 comments

Show HN: Marco, a privacy-first, offline-first email client (IMAP-native, no AI)

https://marcoapp.io/
2•isaachinman•17m ago•0 comments

A 500K-parameter system that recovers invariant physics from observation alone

https://erebus.org/
1•ordinarily•17m ago•0 comments

Quantization from the Ground Up

https://ngrok.com/blog/quantization
4•samwho•17m ago•0 comments

Dan rewrote chardet, relicensed to MIT. Original author broke 15-year silence

https://www.elvex.com/podcast/he-rewrote-chardet-with-claude-the-internet-blew-up-heres-his-take
7•sak84•17m ago•1 comments

Show HN: Dbt-skillz compiles your dbt project into a Claude Code skill

https://github.com/atlasfutures/dbt-skillz
3•davidvgilmore•17m ago•0 comments