4 ms·
Fair! You don’t actually need to install anything and can just generate a text file with the security profile for sandbox-exec. You can do that online at https:
by e1g 7mo ago
Fair! You don’t actually need to install anything and can just generate a text file with the security profile for sandbox-exec. You can do that online at https://agent-safehouse.dev/policy-builder.html https://agent-safehouse.dev/policy-builder.html
Alternatively, you can feed these instructions to your LLM and have it generate you a minimal policy file and a shell wrapper https://agent-safehouse.dev/llm-instructions.txt https://agent-safehouse.dev/llm-instructions.txt
- oneplane 7mo agoThat online builder is very cool, well done! I've been trying out similar things to help internal teams to use systems and languages like Rego (for Open Policy Agent) to have a visual and more 'a la carte' experience when starting out, so they don't have to jump straight to learning all syntax and patterns for a language they might have never seen before.
- e1g 7mo agoThanks, Codex helped to put that together in like 20 minutes. Try feeding your agent the idea about an interactive config builder, give it the upstream URL with your condos, and see if it can whip up something for you.
- chrisweekly 7mo agocondos?
- alsetmusic 7mo agoI would guess conditions. Not certain.
- dummydummy1234 7mo agoReally like the online builder!
- camkego 7mo agoI think if the online builder could have been the whole project, that would be neat! Truly "zero-trust", what I think many HN readers want. Anyway, thanks for building Agent Safehouse.
- e1g 7mo agoThat’s a great idea. I think I’ll restructure the entire project to be based around a collection of community managed rules, a UI generator to build a custom text file from those rules, and an LLM skill so people can evolve their policies themselves. The Bash script will remain in the background as one implementation, but shouldn’t be the only way.