frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Show HN: Sandbox AI-app lifecycle, from build to run

https://capakit.com/
6•leroman•5d ago
Hi HN,

This is a project I've been working on since the beginning of 2025 full time, without funding.

Coding agents have fundamentally changed the way we write software. When you let an agent write code, pull dependencies, and run scripts, you are delegating trust while still keeping the responsibility. You shouldn't have to choose between moving fast with agents and maintaining basic control over your host machine.

Normally, we just inspect the final result, treating the app like a black box. Most security tools only sandbox the app runtime and ignore the build phase.

CapaKit is my attempt to make agent-driven development safe and productive.

Secrets baked into config, dependencies installed with full host access, and arbitrary scripts running during `npm install` are all things you need to take into account.

I started working on CapaKit in early 2025 (originally as mcpgate.com) after Anthropic announced MCP. As the agent ecosystem started to standardize, I wanted to apply what I've learned building with LLMs since GPT-3. Building real AI apps turns out to be really hard: lots of moving parts, from security to devops, on top of a fast-moving ecosystem.

What is special about CapaKit?

CapaKit sandboxes the entire app lifecycle, not just the running code- building, testing, and running, all first class citizens of usability and security.

What that means concretely: - Per-app policies with workload-level isolation. - No inherited host environment, no broad filesystem access. - No network by default — outbound traffic has to be explicitly allowed. - Ephemeral, single-use sandboxes for every build and run. - Secrets resolved on demand instead of hardcoded.

Security with awesome usability: you can upload your AI app Kits to Github and anyone can run them with a single command:

capakit run https://github.com/capakit/hello-world-demo-kit

CapaKit is currently macOS only and is free to use.

Comments

werttalkit•5d ago
Wow!

Show HN: Kage – Shadow any website to a single binary for offline viewing

https://github.com/tamnd/kage
563•tamnd•16h ago•110 comments

Show HN: Trace – Offline Mac meeting transcripts you can flag mid-call

https://traceapp.info
162•AG342•1d ago•59 comments

Show HN: Discover Wikipedia articles popular on Hacker News

https://www.orangecrumbs.com/
114•octopus143•15h ago•26 comments

Show HN: 3D print Z reinforcement via injected loops

https://mgunlogson.github.io/magma/
61•mgunlogson•5d ago•29 comments

Show HN: I used Claude Mythos to build my startup in 1 day

https://www.brandlm.ai/
3•trungnx2605•3h ago•1 comments

Show HN: AwsmAudio – a WebAudio editor with native MCP

https://audio.awsm.fun
2•dakom•3h ago•0 comments

Show HN: Prela – A Compositional and Controllable Query Language

https://prela-lang.org
2•remywang•5h ago•0 comments

Show HN: Dream Server – Turn your PC, Mac, or Linux box into a private AI server

https://github.com/Light-Heart-Labs/DreamServer
6•dreamserver•6h ago•0 comments

Show HN: I am building a map of people who lived in the Roman Empire

https://new.roman-names.com/
201•metiscus•4d ago•46 comments

Show HN: Paca – Lightweight Jira alternative for human-AI collaboration

https://github.com/Paca-AI/paca
165•pikann22•1d ago•60 comments

Show HN: Philosophy for Kids

https://philosophy.ocaho.com/
12•rahimnathwani•15h ago•7 comments

Show HN: Dual YOLOv8n UAV Detection on RK3588S at 42 FPS Using NPU

https://github.com/alebal123bal/khadas_yolov8n_multithread
69•alebal123bal•18h ago•9 comments

Show HN: Homebrew 6.0.0

https://brew.sh/2026/06/11/homebrew-6.0.0/
1458•mikemcquaid•3d ago•360 comments

Show HN: Coding agent with algebraic memory (VSA) instead of RAG

https://github.com/vitaliyfedotovpro-art/raidho
3•astrumverum•9h ago•1 comments

Show HN: Wtdb – give every Git worktree its own database

https://github.com/willhackett/wtdb
3•whh•9h ago•0 comments

Show HN: A-C Coupling – Deterministic Data Decomposition in O(n) with No Search

https://zenodo.org/records/20693980
3•A19dammer91•10h ago•0 comments

Show HN: Bastion – isolated Linux VMs for background coding agents

https://bastion.computer/
28•almostlit•1d ago•2 comments

Show HN: Putt.day a daily mini golf game

https://putt.day/
312•ellg•2d ago•110 comments

Show HN: Lightweight Task queue on Erlang/OTP, SQLite-backed, no overengineering

https://github.com/entGriff/ezra
73•ent1c3d•4d ago•11 comments

Show HN: Is Fable 5 available? (it is not)

https://isfable5available.com
5•bArmageddon•10h ago•0 comments

Show HN: 2 Weeks of Hallucinate – The Photo Gallery

https://hallucinate.site/gallery
72•stagas•1d ago•24 comments

Show HN: Solaris the Thinking Ocean Simulator

https://solaris.franzai.com/
7•franze•12h ago•4 comments

Show HN: I run a vision model on every screenshot, locally, on a 4GB GPU

https://github.com/ayushh0110/ScreenMind
34•skye0110•1d ago•5 comments

Show HN: FablePool – pool money behind a prompt, and Fable builds it in public

https://fablepool.com
522•matthewbarras•3d ago•274 comments

Show HN: Ray Hosting – Topology-aware game server orchestrator made from scratch

https://ray-hosting.com/en-US
3•bardhyliis•13h ago•0 comments

Show HN: I hate typing continue once my CC quota resets

https://github.com/softcane/cc-session-recover
5•pradeep1177•14h ago•2 comments

Show HN: Extend UI – open-source UI kit for modern document apps

https://www.extend.ai/ui
251•kbyatnal•4d ago•81 comments

Show HN: StackScope – I crawled over 40k indie launches to see what they ship

https://stackscope.dev/
65•datafreak_•2d ago•18 comments

Show HN: Quant Picker – which GGUF file fits your model and machine

https://vettedconsumer.com/quant-picker/
20•ermantrout•1d ago•0 comments

Show HN: Boo – Screen-style terminal multiplexer built on libghostty

https://github.com/coder/boo
94•kylecarbs•3d ago•28 comments