frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Securing the Ralph Wiggum Loop – DevSecOps for Autonomous Coding Agents

https://github.com/agairola/securing-ralph-loop
2•agairola•3h ago
Hi HN,

Since AutoGPT in 2023, I’ve been uneasy about fully unsupervised AI agents. I see the productivity upside, but “kick it off and walk away” felt risky.

Recently, the “Ralph Wiggum loop” pattern has gone viral. The idea is simple: An autonomous coding agent runs repeatedly until all PRD items are complete, with fresh context each loop and state stored outside the model in git, JSON, etc.

What bothered me was this part: what protects the system while I’m AFK?

Traditional AI-assisted dev today looks like: AI writes code → human reviews → CI scans → human fixes

What I wanted instead: AI writes code → security scans immediately → AI fixes issues → repeats until secure → escalates if stuck

So I built a prototype that embeds security scanning directly inside the agent loop. The agent runs tools like Semgrep, Grype, Checkov, etc. inside its own session, sees the findings, and iteratively fixes them before anything is committed.

The loop looks like this:

PRD → Agent → Scan → Pass? → Commit Fail → Fix → Retry (3x) → Escalate to human

A few design principles that mattered:

* Baseline delta: pre-existing issues are tracked separately. Only new findings block commits. * Sandbox constraints: no network access, no sudo, no destructive commands. * Human override: nothing is fully autonomous. You can step back in at any point.

Is this bulletproof? Definitely not. Is it production-ready? No. But it’s a starting point for applying DevSecOps thinking to autonomous agents instead of trusting “AI magic.”

Repo link: https://github.com/agairola/securing-ralph-loop

Would love feedback from folks experimenting with agent loops, secure automation, or AI-assisted development gone wrong.

Happy to iterate.

Show HN: Moltbook – A social network for moltbots (clawdbots) to hang out

https://www.moltbook.com/
211•schlichtm•3d ago•828 comments

Show HN: Minimal – Open-Source Community driven Hardened Container Images

https://github.com/rtvkiz/minimal
87•ritvikarya98•14h ago•26 comments

Show HN: OpenJuris – AI legal research with citations from primary sources

https://openjuris.org/
11•Zachzhao•7h ago•2 comments

Show HN: Booktest – review-driven regression testing for LLM / ML behavior

https://github.com/lumoa-oss/booktest
2•arauhala•2h ago•1 comments

Show HN: Securing the Ralph Wiggum Loop – DevSecOps for Autonomous Coding Agents

https://github.com/agairola/securing-ralph-loop
2•agairola•3h ago•0 comments

Show HN: An extensible pub/sub messaging server for edge applications

https://github.com/narwhal-io/narwhal
39•ortuman•3d ago•0 comments

Show HN: I trained a 9M speech model to fix my Mandarin tones

https://simedw.com/2026/01/31/ear-pronunication-via-ctc/
447•simedw•1d ago•135 comments

Show HN: Phage Explorer

https://phage-explorer.org/
117•eigenvalue•1d ago•27 comments

Show HN: Amla Sandbox – WASM bash shell sandbox for AI agents

https://github.com/amlalabs/amla-sandbox
143•souvik1997•1d ago•73 comments

Show HN: Kolibri, a DIY music club in Sweden

https://kolibrinkpg.com/
139•EastLondonCoder•2d ago•30 comments

Show HN: Peptide calculators ask the wrong question. I built a better one

https://www.joyapp.com/peptides/
3•silviogutierrez•8h ago•0 comments

Show HN: Hebo Gateway, an embeddable AI gateway with OpenAI-compatible endpoints

https://github.com/8monkey-ai/hebo-gateway
2•dselvaggio•8h ago•0 comments

Show HN: Pinecone Explorer – Desktop GUI for the Pinecone vector database

https://www.pinecone-explorer.com
30•arsentjev•4d ago•3 comments

Show HN: Pinchwork – A task marketplace where AI agents hire each other

https://github.com/anneschuth/pinchwork
5•aschuth•13h ago•3 comments

Show HN: I built a receipt processor for Paperless-ngx

5•smashah•9h ago•1 comments

Show HN: ToolKuai – Privacy-first, 100% client-side media tools

https://toolkuai.com/
6•indie_max•17h ago•0 comments

Show HN: Cicada – A scripting language that integrates with C

https://github.com/heltilda/cicada
57•briancr•1d ago•38 comments

Show HN: Warden – agent based framework for reviewing code

https://warden.sentry.dev
2•zeeg•12h ago•0 comments

Show HN: Mystral Native – Run JavaScript games natively with WebGPU (no browser)

https://github.com/mystralengine/mystralnative
48•Flux159•4d ago•18 comments

Show HN: ShapedQL – A SQL engine for multi-stage ranking and RAG

https://playground.shaped.ai
80•tullie•4d ago•23 comments

Show HN: Agent Tinman – Autonomous failure discovery for LLM systems

https://github.com/oliveskin/Agent-Tinman
3•oliveskin•15h ago•0 comments

Show HN: Quorum-free replicated state machine built atop S3

https://github.com/io-s2c/s2c
6•mzazaipsc•16h ago•0 comments

Show HN: LemonSlice – Upgrade your voice agents to real-time video

130•lcolucci•4d ago•130 comments

Show HN: The HN Arcade

https://andrewgy8.github.io/hnarcade/
348•yuppiepuppie•3d ago•121 comments

Show HN: Moltbook Overtaken by Shellraiser

https://www.moltbook.com/post/74b073fd-37db-4a32-a9e1-c7652e5c0d59
3•mooball•18h ago•4 comments

Show HN: Free Text-to-Speech Tool – No Signup, 40 Languages

https://texttospeech.site/
5•digi_wares•18h ago•0 comments

Show HN: Bunnie – Use Bun as the templating engine in Rust applications

https://github.com/aspizu/bunnie
3•aspizu•18h ago•0 comments

Show HN: I built an AI conversation partner to practice speaking languages

https://apps.apple.com/us/app/talkbits-speak-naturally/id6756824177
64•omarisbuilding•1d ago•60 comments

Show HN: How We Run 60 Hugging Face Models on 2 GPUs

4•pveldandi•19h ago•20 comments

Show HN: SHDL – A minimal hardware description language built from logic gates

https://github.com/rafa-rrayes/SHDL
48•rafa_rrayes•3d ago•21 comments