frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Enforra – open-source action governance for AI agent tool calls

https://github.com/enforra/enforra
3•rohitguptap•40m ago

Comments

rohitguptap•38m ago
Hi HN,

I’ve been thinking about a gap in how teams are shipping AI agents: system prompts are not a security boundary.

When an agent can issue refunds, run commands, send emails, export data, or modify production systems, the control point should sit before the tool callback executes, not inside the prompt.

Enforra is an open-source SDK that wraps application-owned tool callbacks and returns one of four decisions before the callback runs:

- allow - block - require_approval - log_only

Example: a support agent tries to refund $1,000. Policy says block above $500. The callback never runs. The decision and reason are logged before execution.

It includes:

- Node SDK - YAML policy engine with any/all condition groups - CLI for creating and testing policies - policy simulator for CI - decision trace showing why a policy matched - local JSONL audit logs with secret redaction - optional hash-chain audit integrity - starter policy examples and demos

The OSS core runs locally, makes no hosted API calls, and does not execute your tools remotely.

Install:

npm install @enforra/sdk-node

Try the CLI:

npx @enforra/cli init npx @enforra/cli test

Repo: https://github.com/enforra/enforra

Website: https://enforra.com

Curious whether others building agents have hit this problem: what is your current approach to controlling what your agent is actually allowed to do at runtime?

Solo Dev Kills YouTube Ask

https://www.neotube.ai/
1•walkervin•2m ago•0 comments

Meta Goes Big on the Bayou

https://www.bloomberg.com/features/2026-meta-facebook-ai-data-center-louisiana/
1•littlexsparkee•6m ago•1 comments

1k-year-old dingo bones show that it was injured, cared for, and ritually buried

https://www.popsci.com/environment/dingo-bones-ritual-burial-australia/
2•gmays•8m ago•0 comments

OhMyAdmin – PhpMyAdmin Reimagined with Go, React, and Monaco Editor

https://github.com/aranajhonny/ohmyadmin
2•akatsutki•9m ago•0 comments

Show HN: PrismoDev – local CLI for finding token waste in Claude Code/Codex

https://github.com/shanirsh/prismodev
1•shanirshad•9m ago•0 comments

Show HN: SharpSkill – A LeetCode Alternative with real interview outcomes

https://sharpskill.dev/en/vs/leetcode
2•GiornoJojo•9m ago•0 comments

Russia's War Is Going Badly–On the Ground and in the Air

https://www.wsj.com/world/russias-war-is-going-badlyon-the-ground-and-in-the-air-447ce204
2•JumpCrisscross•11m ago•1 comments

FBI plans tracking system that taps into license plate cameras across US

https://arstechnica.com/tech-policy/2026/05/fbi-seeks-us-wide-access-to-license-plate-cameras-wan...
1•ndr42•13m ago•1 comments

Donald Trump and sons to be 'forever' exempt from tax audits

https://www.ft.com/content/57334fae-a475-4ab0-a202-8df3766927e4
6•doener•14m ago•2 comments

Show HN: Postbear The API Client your terminal has been waiting for

https://github.com/carban/postbear
1•carban•14m ago•0 comments

How Google Is Becoming the New AOL(2014)

https://raventools.com/blog/google-new-aol/
2•rolph•14m ago•0 comments

Printable Blank Calendar Generator

https://blankcal.app/?r=this-month&dp=1
1•zapeterson16•16m ago•0 comments

Google's Ambitious AI Search Changes (Biggest in 25 Years) Are Risky. Here's Why

https://www.inc.com/connor-jewiss/googles-ambitious-ai-search-changes-are-risky-heres-why/91347071
1•connorjewiss•16m ago•0 comments

Xi told Trump that Putin might 'regret' Ukraine invasion

https://www.ft.com/content/567c57b0-6346-43e6-9d14-840a793b4d1d
1•cwwc•17m ago•0 comments

Jigs, Products, and Appearances: The Vibe Coding Distribution Problem

https://trevoragilbert.com/posts/jigs-products-appearances-vibe-coding-distribution/
1•trevoragilbert•17m ago•1 comments

I created Age of Empires 2: The Conquerors

https://twitter.com/i/status/2056763353369063571
2•Michelangelo11•19m ago•0 comments

Trump's deal with government ends his tax audits

https://www.justice.gov/opa/media/1441216/dl
3•defly•20m ago•1 comments

Backup Photos from Google Photos: A Detailed Guide

https://blinkdisk.com/blog/backup-photos-from-google-photos
1•pauxel•22m ago•0 comments

Occupations with the Highest Divorce Rates

https://flowingdata.com/2026/05/07/divorce-and-occupation-2026/
2•gmays•22m ago•0 comments

This was Coworking Tech Week 2026

https://www.coworkingtechweek.com/blog/this-was-coworking-tech-week-2026/
1•inchevd•23m ago•0 comments

Hey Platforms: Add Take It Down to Your Transparency Reports

https://www.techdirt.com/2026/05/19/hey-platforms-add-take-it-down-to-your-transparency-reports/
1•hn_acker•24m ago•0 comments

Sōzune – a reverse proxy built on Sōzu, with Traefik-style autodiscovery

https://github.com/kemeter/sozune
2•Shine-neko•25m ago•2 comments

Concluding the Arc Experiment

https://www.ietf.org/archive/id/draft-adams-arc-experiment-conclusion-00.html
1•upofadown•26m ago•0 comments

Power prices on America's largest grid rose 76%

https://techcrunch.com/2026/05/15/power-prices-are-up-76-on-americas-biggest-grid-and-a-watchdog-...
1•logickkk1•26m ago•0 comments

Flyline: A Bash plugin to replace readline for a modern line editing experience

https://github.com/HalFrgrd/flyline/
4•hellohal•29m ago•3 comments

Purerl: Erlang back end for the PureScript compiler

https://github.com/purerl/purerl
1•tosh•30m ago•0 comments

A frightening weekend doesn't settle the license plate reader debate

https://www.statesman.com/opinion/editorials/article/license-plate-reader-debate-opinion-22264336...
1•jkestner•30m ago•0 comments

Trump Mobile is leaking customer info [video]

https://www.youtube.com/watch?v=voxXDDq58Bk
2•geerlingguy•31m ago•0 comments

Slow Mode

https://blog.val.town/slow-mode
2•yurivish•32m ago•0 comments

Show HN: Cable Detective

https://apps.apple.com/us/app/cable-detective/id6765963737?mt=12
1•franze•33m ago•0 comments