Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Fence

Sandbox CLI commands with network/filesystem restrictions

Details

External ID
46695467
Source
HN
Company
—
Product
Fence
Website domain
github.com
Launched
Jan. 20, 2026
Cohort
—
Upvotes
78
Upvotes percentile
0.8728590250329381
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

Hi HN!Fence wraps any command in a sandbox that blocks network by default and restricts filesystem writes. Useful for running semi-trusted code (package installs, build scripts, unfamiliar repos) with controlled side effects, or even just blocking tools that phone home.> fence curl https://example.com # -> blocked> fence -t code -- npm install # -> template with registries allowed> fence -m -- npm install # -> monitor mode: see what gets blockedOne use-case is to use it with AI coding agents to reduce the risk of running agents with fewer interactive permission prompts:> fence -t code -- claude --dangerously-skip-permissionsYou can import existing Claude Code permissions with `fence import --claude`.Fence uses OS-native sandboxing (macOS sandbox-exec, Linux bubblewrap) + local HTTP/SOCKS proxies for domain filtering.Why I built this: I work on Tusk Drift, a system to record and replay real traffic as API tests (https://github.com/Use-Tusk/tusk-drift-cli). I needed a way to sandbox the service under test during replays to block localhost outbound connections (Postgres, Redis) and force the app to use mocks instead of real services. I quickly realized that this could be a general purpose tool that would also be useful as a permission manager across CLI agents.Limitations: Not strong containment against malware. Proxy-based filtering requires programs to respect `HTTP_PROXY`.Curious if others have run into similar needs, and happy to answer any questions!

Enrichment

Theme
Claude integrations and coding agents
Vertical
Security
Function
Dev tools
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
sandboxed cli command execution with restrictions
Manually corrected
False

Could you build this?

Partial A basic CLI wrapper is easy to vibe code, but low-level sandbox isolation of arbitrary binaries across OS platforms requires deep operating system security internals.

What it would actually take: Fence must leverage OS-native isolation primitives: Linux namespaces, cgroups, and seccomp-bpf filters (or `landlock`), and macOS Sandbox (`sandbox-exec` / seatbelt APIs or Endpoint Security framework). Implementing granular network interception and filesystem cow/virtualization without requiring root access requires low-level C or Rust systems programming.

Discussion

20 comments analyzed.

Competitors mentioned: sandbox-runtime (Anthropic), sandvault (MacOS limited user account approach), clodpod (MacOS virtual machine approach), Steam pressure-vessel containers

Concerns raised: Nested bubblewrap sandboxes don't work (namespace nesting limitations), Domain filtering relies on HTTP_PROXY (malware could ignore it), OS sandboxes aren't VM-level isolation (kernel exploits possible), No resource limits or content inspection, Uncertainty about Fargate/ECS/Lambda deployment support

Feature requests: Deny-by-default read access mode with system path allowlist, Resource limits (CPU, memory, fork bomb protection), Extend to API calls and token budget restrictions, Clearer macOS documentation in README

Competitors

Other products that read as similar to this one — 215 launches clear the similarity bar, closest 8 shown.

Attention rank: #33 of 216 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 83 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.