frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Nucleus – enforced permission envelopes for AI agents (Firecracker)

https://github.com/coproduct-opensource/nucleus
3•difc•2h ago
I’ve been building Nucleus because most “agent security” is still policy-only: a config file that says “don’t do bad things,” while the agent can still do them.

Nucleus is an OSS experiment that pairs a small, compositional permission model with runtime enforcement: *side effects are only reachable through an enforcing tool proxy*, inside a Firecracker microVM. The envelope is *non-escalating*: it can only tighten or terminate, never silently relax.

What works today:

* MCP tool proxy with *read / write / run* (enforced inside the microVM) * default-deny egress + DNS allowlist + iptables drift detection (fail-closed) on Linux * time + budget caps enforced * hash-chained audit log + HMAC approval tokens (scoped, expiring) for gated ops

What’s missing (being upfront):

* web/search tools exist in the model but aren’t wired to MCP yet * remote append-only audit storage + attestation are still roadmap * early/rough; targeting “safe to run against sensitive codebases,” not “replace your local terminal”

Most of the code was written with Anthropic tools; I’ve been leaning on tests/fuzzing/proptests to keep it honest.

Would love feedback on: (1) dangerous capability combinations beyond the lethal trifecta, (2) what enforcement gaps you’d want closed first, (3) how you’d evaluate this vs gateway-only approaches.

Show HN: Wikipedia as a doomscrollable social media feed

https://xikipedia.org
338•rebane2001•16h ago•119 comments

Show HN: Apate API mocking/prototyping server and Rust unit test library

https://github.com/rustrum/apate
23•rumatoest•1d ago•8 comments

Show HN: NanoClaw – “Clawdbot” in 500 lines of TS with Apple container isolation

https://github.com/gavrielc/nanoclaw
458•jimminyx•17h ago•175 comments

Show HN: File Markers – Track file status directly in VS Code's Explorer

https://github.com/joneldominic/vscode-file-markers
2•joneldominic•53m ago•1 comments

Show HN: A different approach to intonation training

https://intunetrainer.conpixel.es/
3•ogig•1h ago•1 comments

Show HN: Stelvio – Ship Python to AWS

https://stelvio.dev/
3•michal-stlv•1h ago•1 comments

Show HN: Nucleus – enforced permission envelopes for AI agents (Firecracker)

https://github.com/coproduct-opensource/nucleus
3•difc•2h ago•0 comments

Show HN: Make AI motion videos with text

https://framecall.com/
3•mesmertech•2h ago•2 comments

Show HN: Bullmq-dash – Terminal UI dashboard for BullMQ (zero setup)

https://www.npmjs.com/package/bullmq-dash
2•quanghuynt14•3h ago•0 comments

Show HN: Agents should learn skills on demand. I built Skyll to make it real

https://www.skyll.app/
2•assafe•3h ago•0 comments

Show HN: ÆTHRA – Writing Music as Code

87•CzaxTanmay•3d ago•29 comments

Show HN: Sklad – Secure, offline-first snippet manager (Rust, Tauri v2)

https://github.com/Rench321/sklad
19•rench321•6h ago•6 comments

Show HN: OpenClaw Cloud – run OpenClaw safely in the cloud, no local install

https://openclawcloud.me/
4•stefanopochet•4h ago•0 comments

Show HN: Sandbox Agent SDK – unified API for automating coding agents

https://github.com/rivet-dev/sandbox-agent
40•NathanFlurry•5d ago•4 comments

Show HN: Prism AI – A research agent that generates 2D/3D visualizations

https://github.com/precious112/prism-ai-deep-research
3•PreciousH•6h ago•3 comments

Show HN: Minimal – Open-Source Community driven Hardened Container Images

https://github.com/rtvkiz/minimal
113•ritvikarya98•1d ago•28 comments

Show HN: Voiden – an offline, Git-native API tool built around Markdown

https://github.com/VoidenHQ/voiden
44•dhruv3006•1d ago•28 comments

Show HN: My Open Source Deep Research tools beats Google and I can Prove it

https://github.com/IamLumae/Project-Lutum-Veritas
14•LutumVeritas•21h ago•3 comments

Show HN: Moltbook – A social network for moltbots (clawdbots) to hang out

https://www.moltbook.com/
269•schlichtm•4d ago•868 comments

Show HN: I trained a 9M speech model to fix my Mandarin tones

https://simedw.com/2026/01/31/ear-pronunication-via-ctc/
462•simedw•2d ago•148 comments

Show HN: Zuckerman – minimalist personal AI agent that self-edits its own code

https://github.com/zuckermanai/zuckerman
70•ddaniel10•1d ago•49 comments

Show HN: Phage Explorer

https://phage-explorer.org/
121•eigenvalue•2d ago•34 comments

Show HN: You Are an Agent

https://youareanagent.app
8•robkop•19h ago•0 comments

Show HN: Jetcaller – Make international calls directly from the browser

https://jetcaller.com
2•sankar_builds•11h ago•0 comments

Show HN: Claw-daw – offline, deterministic terminal-first DAW

https://www.clawdaw.com
3•soyadiaoune•12h ago•1 comments

Show HN: Amla Sandbox – WASM bash shell sandbox for AI agents

https://github.com/amlalabs/amla-sandbox
143•souvik1997•3d ago•73 comments

Show HN: ContractShield – AI contract analyser for freelancers

https://contractshield-production.up.railway.app
3•Judd_W•13h ago•0 comments

Show HN: Kolibri, a DIY music club in Sweden

https://kolibrinkpg.com/
142•EastLondonCoder•3d ago•31 comments

Show HN: OpenJuris – AI legal research with citations from primary sources

https://openjuris.org/
18•Zachzhao•1d ago•8 comments

Show HN: An extensible pub/sub messaging server for edge applications

https://github.com/narwhal-io/narwhal
44•ortuman•5d ago•0 comments