docs(research): add Agent Safehouse HN launch and Apple Container 1.0 stable
- agent-sandbox-landscape.md: update agent-safehouse star count (~1.4k → ~1.8k), add HN thread #47301085 link and key discussion notes (creator framing, Simon Willison observation, top community quote on sandboxing being THE major challenge), note Apple Container 1.0 stable (Jun 9 2026) - hn-agent-safety-discourse-july-2026.md: add Agent Safehouse March 12 launch to the sandboxing boom section as context that prefigures the June–July shift in community tone Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -97,7 +97,8 @@ claim that the monetization positioning leans on. See the addendum.
|
|||||||
|
|
||||||
### agent-safehouse
|
### agent-safehouse
|
||||||
- **Source**: https://agent-safehouse.dev/ ; https://github.com/eugene1g/agent-safehouse
|
- **Source**: https://agent-safehouse.dev/ ; https://github.com/eugene1g/agent-safehouse
|
||||||
- **License**: Apache 2.0 (~1,400 stars)
|
- **HN launch**: [#47301085](https://news.ycombinator.com/item?id=47301085) (March 12 2026) — 823 points
|
||||||
|
- **License**: Apache 2.0 (~1,781 stars at launch)
|
||||||
- **Isolation**: macOS `sandbox-exec` (Seatbelt) profiles — kernel-level
|
- **Isolation**: macOS `sandbox-exec` (Seatbelt) profiles — kernel-level
|
||||||
syscall interception, no container.
|
syscall interception, no container.
|
||||||
- **Locality**: Local, macOS only.
|
- **Locality**: Local, macOS only.
|
||||||
@@ -107,6 +108,16 @@ claim that the monetization positioning leans on. See the addendum.
|
|||||||
- **Config**: Shell functions or custom `sandbox-exec` profile files;
|
- **Config**: Shell functions or custom `sandbox-exec` profile files;
|
||||||
LLM-assisted profile generation supported.
|
LLM-assisted profile generation supported.
|
||||||
- **Network policy**: Not addressed.
|
- **Network policy**: Not addressed.
|
||||||
|
- **Notable from HN thread**: Creator acknowledged the project is "just a
|
||||||
|
policy-generator for `sandbox-exec` — no dependencies, no daemons, no
|
||||||
|
subscription; I did put in many hours to identify the minimum required
|
||||||
|
permissions for agents to continue working." Simon Willison noted that
|
||||||
|
evaluating whether a sandboxing tool actually works as intended is hard.
|
||||||
|
Top community sentiment: *"I honestly think that sandboxing is currently
|
||||||
|
THE major challenge that needs to be solved for the tech to fully realise
|
||||||
|
its potential."* The macOS Docker gap (Docker for Mac runs inside a Linux
|
||||||
|
VM, so `sandbox-exec` is the only native primitive for bare-metal macOS
|
||||||
|
processes) was the stated motivation.
|
||||||
- **Maturity**: Active through March 2026.
|
- **Maturity**: Active through March 2026.
|
||||||
|
|
||||||
### matchlock
|
### matchlock
|
||||||
@@ -372,7 +383,7 @@ them.
|
|||||||
| DX: run Claude yolo-style | One command → interactive yolo Claude (`start <agent>`, `--dangerously-skip-permissions` default) | n/a (lib demo) | Wizard + build, then run claude inside (Linux only) | One-command wrapper (`safehouse claude --dangerously-skip-permissions`) | CLI: run a cmd in a VM (not a Claude wrapper) | Hosted (`tilde exec`), not local-native | SDK code required (build the run yourself) | CLI/MCP: sandbox-as-a-tool for the agent, not a wrapper around it | SSH into a named machine, run claude there | Stand up a cluster + drive via E2B SDK | CI-oriented, not a Claude wrapper | MCP server: `claude mcp add container-use -- container-use stdio` | One command: `sbx` wraps claude with `--dangerously-skip-permissions` default | Library/wrapper, not a standalone CLI |
|
| DX: run Claude yolo-style | One command → interactive yolo Claude (`start <agent>`, `--dangerously-skip-permissions` default) | n/a (lib demo) | Wizard + build, then run claude inside (Linux only) | One-command wrapper (`safehouse claude --dangerously-skip-permissions`) | CLI: run a cmd in a VM (not a Claude wrapper) | Hosted (`tilde exec`), not local-native | SDK code required (build the run yourself) | CLI/MCP: sandbox-as-a-tool for the agent, not a wrapper around it | SSH into a named machine, run claude there | Stand up a cluster + drive via E2B SDK | CI-oriented, not a Claude wrapper | MCP server: `claude mcp add container-use -- container-use stdio` | One command: `sbx` wraps claude with `--dangerously-skip-permissions` default | Library/wrapper, not a standalone CLI |
|
||||||
| Config | JSON manifest (bottles + agents) | Programmatic refs | CLI wizard | Profile files / shell fns | CLI / SDK | DSL + CLI + SDK | SDK | CLI / SDK / MCP | TOML Smolfile | E2B-compatible SDK | cleanroom.yaml in repo | None (no policy config) | Preset levels at launch | Programmatic per-invocation (allow/deny lists) |
|
| Config | JSON manifest (bottles + agents) | Programmatic refs | CLI wizard | Profile files / shell fns | CLI / SDK | DSL + CLI + SDK | SDK | CLI / SDK / MCP | TOML Smolfile | E2B-compatible SDK | cleanroom.yaml in repo | None (no policy config) | Preset levels at launch | Programmatic per-invocation (allow/deny lists) |
|
||||||
| Agent-tailored policy | Yes — bottle/agent split; declarative per-role egress + credentials; composable via `extends:` | Partial — capability model scopes per-agent, but no declarative role manifest | No | Partial — per-agent profile files (Seatbelt); no egress | No | Yes — per-agent DSL RBAC (allow/deny/approve per action/repo/agent) | No | No | No | No — per-sandbox SDK config, not role-scoped | Partial — per-repo cleanroom.yaml, not per-role | No | No — network presets only | No |
|
| Agent-tailored policy | Yes — bottle/agent split; declarative per-role egress + credentials; composable via `extends:` | Partial — capability model scopes per-agent, but no declarative role manifest | No | Partial — per-agent profile files (Seatbelt); no egress | No | Yes — per-agent DSL RBAC (allow/deny/approve per action/repo/agent) | No | No | No | No — per-sandbox SDK config, not role-scoped | Partial — per-repo cleanroom.yaml, not per-role | No | No — network presets only | No |
|
||||||
| Maturity | Active July 2026 | Research (2022+) | Early (~66 ⭐) | Active (~1.4k ⭐) | Experimental (~574 ⭐) | Private preview | YC, ~4.7k ⭐ | YC, ~6k ⭐, beta | ~3.1k ⭐ | Tencent, prod, ~10.4k ⭐ | Active (Buildkite product) | Early development | GA 2026 | Early research preview |
|
| Maturity | Active July 2026 | Research (2022+) | Early (~66 ⭐) | Active (~1.8k ⭐) | Experimental (~574 ⭐) | Private preview | YC, ~4.7k ⭐ | YC, ~6k ⭐, beta | ~3.1k ⭐ | Tencent, prod, ~10.4k ⭐ | Active (Buildkite product) | Early development | GA 2026 | Early research preview |
|
||||||
|
|
||||||
## What's closest, what's different
|
## What's closest, what's different
|
||||||
|
|
||||||
@@ -385,7 +396,9 @@ keeping Docker only as a legacy fallback; agent-safehouse uses
|
|||||||
`sandbox-exec`; litterbox uses Podman + Landlock. matchlock and
|
`sandbox-exec`; litterbox uses Podman + Landlock. matchlock and
|
||||||
smolmachines are close on *both* the policy side (default-deny net,
|
smolmachines are close on *both* the policy side (default-deny net,
|
||||||
per-host allowlist) and — now that bot-bottle has moved off
|
per-host allowlist) and — now that bot-bottle has moved off
|
||||||
containers-by-default — the microVM isolation primitive.
|
containers-by-default — the microVM isolation primitive. Note: Apple
|
||||||
|
Container 1.0 stable shipped June 9 2026 (frozen CLI and APIs), which
|
||||||
|
makes the macOS backend stable surface area rather than a moving target.
|
||||||
|
|
||||||
**New closest on agent-tailored policy.** Two governance tools are the
|
**New closest on agent-tailored policy.** Two governance tools are the
|
||||||
direct competitors on the "coarse-grained sandbox" axis. **tilde.run**
|
direct competitors on the "coarse-grained sandbox" axis. **tilde.run**
|
||||||
|
|||||||
@@ -43,6 +43,18 @@ surveyed what developers were actually deploying: "containers or YOLO"
|
|||||||
dominated. The honest community mood was that most teams hadn't solved
|
dominated. The honest community mood was that most teams hadn't solved
|
||||||
this and were shipping anyway.
|
this and were shipping anyway.
|
||||||
|
|
||||||
|
The March 12 launch of **Agent Safehouse**
|
||||||
|
([#47301085](https://news.ycombinator.com/item?id=47301085), 823 points)
|
||||||
|
crystallised the community framing: a zero-dep `sandbox-exec` wrapper for
|
||||||
|
macOS that attracted the top comment *"I honestly think that sandboxing is
|
||||||
|
currently THE major challenge that needs to be solved for the tech to fully
|
||||||
|
realise its potential."* The creator's own framing — "no dependencies, no
|
||||||
|
daemons, no subscription; the simplicity is the feature" — and Simon
|
||||||
|
Willison's observation that evaluating whether a sandboxing tool works as
|
||||||
|
intended is itself hard, both prefigure the June–July shift in tone. See
|
||||||
|
[`agent-sandbox-landscape.md`](agent-sandbox-landscape.md) for a full
|
||||||
|
per-project breakdown.
|
||||||
|
|
||||||
## The June–July attack cascade
|
## The June–July attack cascade
|
||||||
|
|
||||||
Six attack patterns broke in quick succession. Together they form the
|
Six attack patterns broke in quick succession. Together they form the
|
||||||
|
|||||||
Reference in New Issue
Block a user