yolo-cage
AI coding agents that can't exfiltrate secrets
Details
- External ID
- 46706796
- Source
- HN
- Company
- —
- Product
- yolo-cage
- Website domain
- github.com
- Launched
- Jan. 21, 2026
- Cohort
- —
- Upvotes
- 60
- Upvotes percentile
- 0.8353096179183136
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
I made this for myself, and it seemed like it might be useful to others. I'd love some feedback, both on the threat model and the tool itself. I hope you find it useful!Backstory: I've been using many agents in parallel as I work on a somewhat ambitious financial analysis tool. I was juggling agents working on epics for the linear solver, the persistence layer, the front-end, and planning for the second-generation solver. I was losing my mind playing whack-a-mole with the permission prompts. YOLO mode felt so tempting. And yet.Then it occurred to me: what if YOLO mode isn't so bad? Decision fatigue is a thing. If I could cap the blast radius of a confused agent, maybe I could just review once. Wouldn't that be safer?So that day, while my kids were taking a nap, I decided to see if I could put YOLO-mode Claude inside a sandbox that blocks exfiltration and regulates git access. The result is yolo-cage.Also: the AI wrote its own containment system from inside the system's own prototype. Which is either very aligned or very meta, depending on how you look at it.
Enrichment
- Theme
- AI agent frameworks and developer tools
- Vertical
- Security
- Function
- Agent / copilot
- Audience
- Developer
- AI stance
- AI-native
- Project type
- Hobby / open-source project
- Normalized one-liner
- ai coding agents with secret protection
- Manually corrected
- False
Could you build this?
No Preventing arbitrary AI coding agents from exfiltrating secrets requires deep security sandboxing, Linux kernel namespaces, seccomp filtering, and strict network/socket virtualization.
What it would actually take: A robust solution requires an isolated execution environment using microVMs (like Firecracker) or hard Linux containers configured with strict cgroups, user/network namespaces, and custom eBPF/seccomp syscall filtering. It must feature an egress-filtering proxy that performs deep packet inspection or TLS interception to prevent steganographic exfiltration and covert channels while preserving legitimate agent package installations.
Discussion
20 comments analyzed.
Competitors mentioned: cordum.io, docker-nixuser, vibebin, Claude Code CLI
Concerns raised: AI agents can hallucinate non-existent packages causing supply chain attacks, Build-time backdoor injection risk (weakened RNG, leaked keys, disabled SSL verification), Plaintext checks are not strong enough to prevent LLM violations of intent, AI-generated filters may not provide adequate protection if bypassed, Arbitrary command execution in production is higher risk than code changes
Feature requests: IDE integration support, Strict egress filtering via proxy for package fetching, Supervisor-mediated external access instead of direct agent connections, Network isolation rather than content-based filtering, Informative rejection messages explaining reasons for restrictions
Competitors
Other products that read as similar to this one — 337 launches clear the similarity bar, closest 8 shown.
Attention rank: #62 of 338 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 82 days after the earliest competitor.
- RewardHackBench: Using sandboxes to stop agents from cheating · hn · 2026-06-17 · 9 upvotes · similarity 0.48
- Huzzah · hn · 2026-08-20 · 384 upvotes · similarity 0.45
- Git for AI Agents · hn · 2026-05-08 · 129 upvotes · similarity 0.45
- Git for AI Agents · hn · 2026-05-07 · 5 upvotes · similarity 0.45
- Computer Agents · hn · 2026-03-01 · 7 upvotes · similarity 0.45
- Era · hn · 2025-11-27 · 62 upvotes · similarity 0.45
- Agentspace · hn · 2026-06-17 · 5 upvotes · similarity 0.43
- Maxxwell · hn · 2026-09-09 · 11 upvotes · similarity 0.42
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a agent / copilot tool for Agriculture yet.