frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: How are you sandboxing coding agents?

12•m-hodges•3h ago
I've seen people rely on built-in sandboxes, use git worktrees (sometimes inside devcontainers), or run the whole agent inside a Linux VM with minimal host mounts. On Linux, I’ve also seen firejail/bubblewrap mentioned.

For folks actually using these tools day-to-day:

What’s your default setup?

Have you had any "learned the hard way" moments?

What tradeoff (safety vs convenience vs parallelism) has mattered most in practice?

I'm less interested in theoretical best practices than what's actually holding up under real use.

Comments

netcoyote•3h ago
I use a Mac, and wanted to be able to run MacOS programs like Xcode and iOS simulator, so I wrote a couple of different sandbox projects:

- SandVault (https://github.com/webcoyote/sandvault) runs the AI agent in a low-privilege account

- ClodPod (https://github.com/webcoyote/clodpod) runs the AI agent inside a MacOS VM

In both cases I map my code directories using shares/mounts.

I find that I use the low-privilege account solution more because it's easier to setup and doesn't require the overhead of a full VM

sixhobbits•2h ago
I have time machine and just let them fly with --dangerously-skip-permissions on my Mac. Worst thing it's done is back up a database, delete the database, and then run git clean locally which also wiped out the backup, so I'm not saying there are no dangers but honestly I've made worse mistakes and probably more frequently so I generally trust Claude with about the same level of access as me now.

Most common is deleting files etc but if you're using git and have backups it's barely noticeable

OJFord•39m ago
How are you going to notice that while working on ~/projects/acme3000 it for some reason deleted ~/photos/2003/once-in-a-lifetime-holiday/?

Backups are great when you know you need to restore.

gl-prod•1h ago
I spin a Firecracker VM with a custom image that has all the things I need.
stavros•1h ago
I wrote a small utility that wraps commands in Docker: https://github.com/skorokithakis/dox
jomcgi•1h ago
I have a web ui for managing / interacting with opencode sessions. Everything runs as a pod in my homelab cluster so I can let them "bypass" permissions and just restrict the pods.

I wanted something like Claude code web with access to more models / local LLMs / my monorepo tooling, so far it's been great.

The output is a PR so it's hard for it to break anything.

The biggest benefit is probably that it makes it easier to start stuff when I'm out - feels like a much better use of downtime like I'm not waiting to get home to start a session after I have an idea.

The monorepo tooling is a bit win too, for a bunch of things I just have 1 way to do it and clear instructions for them to use the binaries that get bundled into new sessions so it gets things "right" more often.

aussieguy1234•1h ago
I run vscode based agents in Linux, mostly Kilo Code

After a bit of tinkering I was able to get it to all run fine in Firejail, I wrote a guide here https://softwareengineeringstandard.com/2025/12/15/ai-agents...

Fairly basic, limits the agents write access to my projects, all of which are backed up in git.

yomismoaqui•11m ago
Using Claude Code and Amp (free mode) with no sandbox.

I don't run Claude Code in YOLO mode, I just approve commands the first time I'm asked about them.

Using them since July I haven't found any problem with data loss and the clanker have not tried to delete my $HOME.

Show HN: Ez FFmpeg – Video editing in plain English

http://npmjs.com/package/ezff
103•josharsh•3h ago•33 comments

Cursed Bundler: Using go get to install Ruby Gems

https://nesbitt.io/2025/12/25/cursed-bundler-using-go-get-to-install-ruby-gems.html
5•SPBS•50m ago•1 comments

Mruby: Ruby for Embedded Systems

https://github.com/mruby/mruby
45•nateb2022•5d ago•10 comments

How uv got so fast

https://nesbitt.io/2025/12/26/how-uv-got-so-fast.html
957•zdw•18h ago•321 comments

AI Police Reports: Year in Review

https://www.eff.org/deeplinks/2025/12/ai-police-reports-year-review
137•hn_acker•3d ago•86 comments

Exe.dev

https://exe.dev/
256•achairapart•12h ago•123 comments

Always bet on text (2014)

https://graydon2.dreamwidth.org/193447.html
232•jesseduffield•12h ago•118 comments

Langjam-Gamejam Devlog: Making a language, compiler, VM and 5 games in 52 hours

https://github.com/Syn-Nine/gar-lang/blob/main/DEVLOG.md
53•suioir•5d ago•4 comments

Intertapes – collection of found cassette tapes from different locations

https://intertapes.net/
7•wallflower•5d ago•0 comments

QNX Self-Hosted Developer Desktop

https://devblog.qnx.com/qnx-self-hosted-developer-desktop-initial-release/
166•transpute•10h ago•90 comments

The best things and stuff of 2025

https://blog.fogus.me/2025/12/23/the-best-things-and-stuff-of-2025.html
276•adityaathalye•3d ago•28 comments

Experts explore new mushroom which causes fairytale-like hallucinations

https://nhmu.utah.edu/articles/experts-explore-new-mushroom-which-causes-fairytale-hallucinations
405•astronads•18h ago•220 comments

Package managers keep using Git as a database, it never works out

https://nesbitt.io/2025/12/24/package-managers-keep-using-git-as-a-database.html
650•birdculture•23h ago•368 comments

More dynamic cronjobs

https://george.mand.is/2025/09/more-dynamic-cronjobs/
53•0928374082•5h ago•10 comments

Some Junk Theorems in Lean

https://github.com/James-Hanson/junk-theorems-in-lean
19•saithound•4d ago•4 comments

Publishing your work increases your luck

https://github.com/readme/guides/publishing-your-work
141•magoghm•11h ago•45 comments

CloudFlare is ruining the internet (for me)

https://www.slashgeek.net/2016/05/17/cloudflare-is-ruining-the-internet-for-me/
52•nomilk•2h ago•37 comments

One million (small web) screenshots

https://nry.me/posts/2025-10-09/small-web-screenshots/
110•squidhunter•4d ago•11 comments

How Lewis Carroll computed determinants (2023)

https://www.johndcook.com/blog/2023/07/10/lewis-carroll-determinants/
186•tzury•16h ago•46 comments

Researchers develop a camera that can focus on different distances at once

https://engineering.cmu.edu/news-events/news/2025/12/19-perfect-shot.html
56•gnabgib•3d ago•17 comments

SIMD City: Auto-Vectorisation

https://xania.org/202512/20-simd-city
47•brewmarche•6d ago•8 comments

Show HN: Witr – Explain why a process is running on your Linux system

https://github.com/pranshuparmar/witr
337•pranshuparmar•20h ago•58 comments

Inside the proton, the ‘most complicated thing you could possibly imagine’ (2022)

https://www.quantamagazine.org/inside-the-proton-the-most-complicated-thing-imaginable-20221019/
59•tzury•8h ago•10 comments

Toys with the highest play-time and lowest clean-up-time

https://joannabregan.substack.com/p/toys-with-the-highest-play-time-and
395•surprisetalk•15h ago•234 comments

T-Ruby is Ruby with syntax for types

https://type-ruby.github.io/
135•thunderbong•15h ago•104 comments

LearnixOS

https://www.learnix-os.com
238•gtirloni•22h ago•92 comments

Moravec's Paradox and the Robot Olympics

https://www.physicalintelligence.company/blog/olympics
65•beklein•3d ago•7 comments

Show HN: Xcc700: Self-hosting mini C compiler for ESP32 (Xtensa) in 700 lines

https://github.com/valdanylchuk/xcc700
128•isitcontent•20h ago•23 comments

Parasites plagued Roman soldiers at Hadrian's Wall

https://arstechnica.com/science/2025/12/study-roman-soldiers-battled-parasites-at-hadrians-wall/
69•sipofwater•1w ago•44 comments

Ask HN: What did you read in 2025?

240•kwar13•23h ago•343 comments