AI October 9, 2026 mixed ⇧ 759 pts across 5 threads

Agents need sandboxes, and the human-in-the-loop part is awkward

MXC launched as a sandboxed code execution system. The top reaction asked why everyone is building their own agent runtime when a sandboxing policy design, like Unix permissions, should come first. Defenders called it a friendlier frontend over bubblewrap, seatbelt and process containers, which are painful to configure consistently. A separate post lets agents draw big arrows, boxes and text on your screen. Its pitch is that agents "keep hitting the same wall, the part that only a human may do." The reply was blunt: if you're just there to click sudo for the bot, give it root and be done.

On the lighter end of the same wave, people used Claude Code to find a possible new planet, port Quake to safe Rust (the first question was whether an LLM did it), and sketch a Home Assistant dashboard from a floor plan. A Show HN also shipped OSC 7501, a terminal protocol for program status, so tools can report what they're doing.

The through-line is that the agent runtime layer is unsettled. Everyone is hand-rolling isolation, permissions and status reporting, and nobody has settled how a person fits into the loop without becoming a rubber stamp.


So what?

There's open ground in agent infrastructure: standard permission models, sandboxes, and approval interfaces that don't train users to click yes. If you ship agents to customers, how you handle permissions will matter as much as capability. Treat a fragmented market as a reason to wrap or adopt an existing primitive rather than build a fifth one.

Read these