Hacker News new | ask | show | jobs
by LuD1161 18 days ago
With agentjail (github.com/LuD1161/agentjail), I've tried to contain coding agents in os-native sandboxes (sbpl for macos and similarly for linux) + policy guardrails evaluated by Open Policy Agent (OPA), policies written in rego.

Protocol aware network proxy coming soon Then you can match a DSL and block particular network requests.

This ensures you no longer fear --dangerously-skip-permissions and stop babysitting agents

What else would you want to see in this project? Please star the repo, if you like the idea :)

1 comments

Firecracker microVMs are safest. That's what I added to my repo; see above.