Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Ash, an Agent Sandbox for Mac

Details

External ID
47324461
Source
HN
Company
—
Product
Ash, an Agent Sandbox for Mac
Website domain
ashell.dev
Launched
March 10, 2026
Cohort
—
Upvotes
16
Upvotes percentile
0.6968019680196802
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

Ash is a macOS sandbox that restricts AI coding agents. It limits access to files, networks, processes, IO devices, and environment variables. You can use Ash with any CLI coding agent by wrapping it in a single command: `ash run -- <agent>`. I typically use it with Claude to stay safe while avoiding repetitive prompts: `ash run -- claude --dangerously-skip-permissions`.Ash restricts resources via the Endpoint Security and Network Extension frameworks. These frameworks are significantly more powerful than the sandbox-exec tool.Each session is driven by a policy file. Any out-of-policy action is denied by default. You can audit denials in the GUI app, which lets you view out-of-policy actions and retroactively add them to your policy file.Ash also comes with tools for building policies. You can use an "observation session" to watch the typical behavior of a coding agent and capture that behavior in a policy file for future sandbox sessions. Linting, formatting, and rule merging are all built into the Ash CLI to keep your policy files concise and maintainable.Download Ash at https://ashell.dev

Enrichment

Theme
developer tools for AI agents
Vertical
Horizontal
Function
Agent / copilot
Audience
Developer
AI stance
AI-native
Project type
Commercial product
Normalized one-liner
sandbox environment for ai agents on macos
Manually corrected
False

Could you build this?

No Ash relies on low-level macOS system APIs like Endpoint Security (EndpointSecurity.framework) and Network Extensions, which require Apple-entitled kernel/system privileges and deep security engineering.

What it would actually take: Building Ash requires Swift/Objective-C/C++ leveraging Apple's Endpoint Security API (es_new_client, ES_EVENT_TYPE_AUTH_*) to intercept filesystem, process execution, and device access, alongside Network Extension (NEFilterDataProvider) for network filtering. The hard part is managing system extension lifecycles, surviving OS updates, handling high-throughput event queues without deadlocking or lagging the OS, and obtaining Apple developer entitlements for system extensions.

Discussion

15 comments analyzed.

Competitors mentioned: Claude Code (CC) sandbox, sandbox-exec (macOS builtin), Keypo (secure enclave encryption), VM-based sandboxing, Container-based sandboxing

Concerns raised: Name conflicts with existing 'ash shell' (Almquist shell, 36 years old), Name overloaded/used by many other projects, Cumbersome permissions setup process (multiple Endpoint Security/Network Extension permissions), Missing Full Disk Access permission in UI setup flow, GitHub login broken (404 error)

Feature requests: Process-specific network access restrictions, Per-process or per-command outbound network filtering, GitHub issue/bug report repository, Streamlined permissions setup walkthrough

Competitors

Other products that read as similar to this one — 184 launches clear the similarity bar, closest 8 shown.

Attention rank: #64 of 185 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 109 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a agent / copilot tool for Agriculture yet.