Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
omrimaya
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
We eliminated 1,400 CVEs in NanoClaw's container images
(echo.ai)
70 points
by
omrimaya
2mo ago
|
47 comments
2.
▲
by
omrimaya
7mo ago
The capability-based permission propagation is the part I'd want to stress-test first, in practice we found that the interesting failure mode isn't the agent escaping its sandbox, it's the agent calling back into the host in
3.
▲
by
omrimaya
7mo ago
The one-line summary + lazy-load pattern is exactly where we landed too after trying to stuff schemas into context. What I'd add: the harder problem is invalidation, those skill files accumulate stale knowledge fast, and the agent sile
4.
▲
by
omrimaya
7mo ago
The "infrastructure instead of a library" pattern is everywhere in the LLM tooling space right now. We went through the same decision point, stood up LiteLLM, ran it for a week, then ripped it out because the operational surface w
5.
▲
by
omrimaya
7mo ago
The design decision I find most interesting here is ephemeral-by-default with opt-in checkpointing, that inversion of the usual "persist everything, clean up manually" model fits agent code execution well. Most sandboxing approach