frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Show HN: Sandbox AI-app lifecycle, from build to run

https://capakit.com/
4•leroman•1h ago
Hi HN,

This is a project I've been working on since the beginning of 2025 full time, without funding.

Coding agents have fundamentally changed the way we write software. When you let an agent write code, pull dependencies, and run scripts, you are delegating trust while still keeping the responsibility. You shouldn't have to choose between moving fast with agents and maintaining basic control over your host machine.

Normally, we just inspect the final result, treating the app like a black box. Most security tools only sandbox the app runtime and ignore the build phase.

CapaKit is my attempt to make agent-driven development safe and productive.

Secrets baked into config, dependencies installed with full host access, and arbitrary scripts running during `npm install` are all things you need to take into account.

I started working on CapaKit in early 2025 (originally as mcpgate.com) after Anthropic announced MCP. As the agent ecosystem started to standardize, I wanted to apply what I've learned building with LLMs since GPT-3. Building real AI apps turns out to be really hard: lots of moving parts, from security to devops, on top of a fast-moving ecosystem.

What is special about CapaKit?

CapaKit sandboxes the entire app lifecycle, not just the running code- building, testing, and running, all first class citizens of usability and security.

What that means concretely: - Per-app policies with workload-level isolation. - No inherited host environment, no broad filesystem access. - No network by default — outbound traffic has to be explicitly allowed. - Ephemeral, single-use sandboxes for every build and run. - Secrets resolved on demand instead of hardcoded.

Security with awesome usability: you can upload your AI app Kits to Github and anyone can run them with a single command:

capakit run https://github.com/capakit/hello-world-demo-kit

CapaKit is currently macOS only and is free to use.

Comments

werttalkit•1h ago
Wow!

ChromiumFish – Open-source fingerprint-hardened Browser for Scraping

https://github.com/arman-bd/chromiumfish
1•armanified•56s ago•1 comments

Show HN: Proquiro – Land acquisition software for Indian real estate teams

https://proquiro.com
1•nvignesh•1m ago•0 comments

Show HN: Terra – Off-market real estate sourcing, with research and AI modelling

https://terraconsole.com
1•vampiregrey•2m ago•0 comments

Or Equivalent Experience: Lazy Mistakes in Hiring and the Truth Behind Jobs Data

https://substack.norabble.com/p/or-equivalent-experience
1•nedruod•4m ago•0 comments

FCC Wants to Kill Burner Phones by Forcing Telecoms to Get All Customers' IDs

https://www.404media.co/fcc-wants-to-kill-burner-phones-by-forcing-telecoms-to-get-all-customers-...
1•berlianta•4m ago•0 comments

Malicious PyPI Wheels Target Bioinformatics and MCP Developers

https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-worms-target-bioinformatics-and-mcp-deve...
1•fbuilesv•5m ago•0 comments

Gemini 3.5 Live Translate

https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-live-3-5-translate/
1•berlianta•6m ago•0 comments

GoSkoly

1•Juancabrera123•7m ago•0 comments

Drone Boat Rescues Crew of Downed U.S. Apache Helicopter Near Hormuz

https://www.wsj.com/world/middle-east/apache-helicopter-crash-coast-oman-4de26c6d
2•jawiggins•7m ago•0 comments

Claude Desktop for Linux

https://github.com/aaddrick/claude-desktop-debian
1•speckx•8m ago•0 comments

Why WebRTC beats WebSockets for realtime voice AI

https://livekit.com/blog/why-webrtc-beats-websockets-for-voice-ai-agents
1•jrm-veris•9m ago•0 comments

Show HN: RiddleRun – AI run end-to-end browser tests

https://github.com/raeudigerRaeffi/riddlerun
2•raffasch123•12m ago•0 comments

How to validate a business idea in 10 minutes using AI business frameworks

https://manateavagner.com/news/empire-generator-validate-idea
1•manateavagner•13m ago•0 comments

AI in the Workplace – Part 2

1•localhoster•13m ago•0 comments

Using Optical Aberrations to Distinguish Real Astronomical Transients

https://arxiv.org/abs/2606.08319
2•solarist•14m ago•0 comments

Ronin

https://100r.co/site/ronin.html
1•tosh•14m ago•0 comments

Watch These Judges Rip into Lawyers for Citing Cases That Don't Exist

https://www.404media.co/new-york-court-ai-citations-landberg-case/
2•b-man•15m ago•0 comments

Built to benefit everyone: our plan

https://openai.com/index/built-to-benefit-everyone-our-plan/
1•mstevens•15m ago•1 comments

Scott and Mark Learn to Vibe Check with Steve Sanderson [video]

https://www.youtube.com/watch?v=zh6fMtL_cSM
1•joshka•16m ago•0 comments

Flat Datacenter Networks at Scale

https://perspectives.mvdirona.com/2026/06/flat-datacenter-networks-at-scale/
1•zdw•16m ago•0 comments

Position paper: Agents should train on their histories, not just retrieve them

https://zenodo.org/records/20583812
1•iamevandrake•16m ago•0 comments

Solar Energy Saves Europeans $135M a Day

https://cleantechnica.com/2026/06/08/solar-energy-saves-europeans-135-million-a-day/
5•vrganj•16m ago•0 comments

Show HN: Open-source plugin that builds single-file HTML decks for coding agents

https://github.com/FluidForm-ai/fluiddocs-deck-builder
1•naggarwal29•17m ago•0 comments

Pentagon Says Alibaba, Baidu, BYD, and Unitree Support China's Military

https://techcrunch.com/2026/06/08/pentagon-says-alibaba-baidu-byd-and-unitree-support-chinas-mili...
1•netfortius•17m ago•3 comments

Show HN: Dochost – turn AI output into a shareable link

https://dochost.io
1•sailorpro•17m ago•0 comments

The Math of Fitting In

https://omnia.sas.upenn.edu/story/math-fitting-in-language-acquisition-social-norms-yang
1•wjb3•18m ago•0 comments

Efficient Training on Multiple Consumer GPUs with RoundPipe

https://arxiv.org/abs/2604.27085
1•PaulHoule•19m ago•0 comments

Govt websites, security, and the dreaded f12

https://github.com/Evillare/EMCCA---potential-berach-in-authentication-and-security/tree/main
1•Evillare•19m ago•0 comments

Noyb launches class action over CRIF's scoring system in Austria

https://noyb.eu/en/secret-scoring-join-crif-class-action-now
1•buzer•19m ago•0 comments

Even light drinking raises risk of cancer, heart disease, and early death

https://www.eurekalert.org/news-releases/1131274
5•stringfood•22m ago•1 comments