Cupcake
Better performance and security for coding agents (via OPA)
Details
- External ID
- 46218813
- Source
- HN
- Company
- —
- Product
- Cupcake
- Website domain
- github.com
- Launched
- Dec. 10, 2025
- Cohort
- —
- Upvotes
- 12
- Upvotes percentile
- 0.5562977099236641
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
We're releasing early efforts on coding agent governance with Cupcake [1] - an open-source policy enforcement layer with native integrations. You write rules in policy-as-code (OPA/Rego), and Cupcake integrates them into the agent runtime via Hooks.See it in action (Desktop only): https://cupcake-policy-studio.vercel.app/example-policies/se...Help us build: https://github.com/eqtylab/cupcakeWe are EQTY Lab, our mission is verifiable AI (identity, provenance, and governance). With the rise of capable agents like Claude Code, it became immediately clear that those deploying these agents need the ability to conduct their own alignment and safety controls. We can’t rely solely on the frontier labs.This is why we created the feature request for Hooks in Claude Code [2], and pivoted away from filesystem and OS-level monitoring once those hooks were implemented. Hooks provide the critical points we need:* Evaluation: Checking agent intent and actions.* Prevention: Stopping unsafe or unwanted actions.* Modification: Adjusting the agent's output before execution.Policy-as-Code with OPA/Rego - While many agent security papers suggest similar policy architectures using invented DSLs, Cupcake is fundamentally built on Open Policy Agent (OPA) and its policy language, Rego [3].We chose Rego because it is:* Industry-Robust: Widely adopted across enterprise DevSecOps and cloud-native environments.* Purpose-Built: Offers unique, mature advantages for defining, managing, and enforcing policy as code.* Enterprise-Oriented: This makes Cupcake compatible with existing enterprise governance frameworks.Cupcake is released under the Apache-2.0 license. We will formalize a path to v1.0.0 in Q1 of 2026. This is an early preview version. The goal with Cupcake is not suppression, but to ensure an agent is able to drive fast without crashing. To collaborate, or join forces: ramos at eqtylab dot io.[1] https://github.com/eqtylab/cupcake[2] https://github.com/anthropics/claude-code/issues/712[3] https://www.openpolicyagent.org/
Enrichment
- Theme
- AI agent frameworks and developer tools
- Vertical
- Horizontal
- Function
- Agent / copilot
- Audience
- Developer
- AI stance
- AI feature
- Project type
- Commercial product
- Normalized one-liner
- performance and security for coding agents
- Manually corrected
- False
Could you build this?
Yes Integrating an existing policy engine like Open Policy Agent (OPA) into agent tool-calling hooks via standard APIs and middleware is straightforward to build with AI assistance.
Discussion
1 comment analyzed.
Competitors
Other products that read as similar to this one — 159 launches clear the similarity bar, closest 8 shown.
Attention rank: #77 of 160 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 9 days after the earliest competitor.
- AI Coding Agent Guardrails enforced at runtime · hn · 2026-04-20 · 5 upvotes · similarity 0.40
- AgentKanban for VS Code · hn · 2026-05-13 · 5 upvotes · similarity 0.40
- Sandbox Agent SDK · hn · 2026-01-28 · 41 upvotes · similarity 0.39
- Cupcake-DRCP · ph · 2026-09-23 · 1 upvotes · similarity 0.39
- Rigour Labs · ph · 2026-09-15 · 2 upvotes · similarity 0.39
- Policy enforcement for Claude Code, Cursor, and Codex · hn · 2026-07-09 · 13 upvotes · similarity 0.39
- AgentBox · hn · 2026-04-23 · 8 upvotes · similarity 0.39
- Open Agents · ph · 2026-04-14 · 161 upvotes · similarity 0.38
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a agent / copilot tool for Agriculture yet.