Mistle
Open-source infrastructure for running sandboxed coding agents
Details
- External ID
- 48122542
- Source
- HN
- Company
- —
- Product
- Mistle
- Website domain
- github.com
- Launched
- May 13, 2026
- Cohort
- —
- Upvotes
- 6
- Upvotes percentile
- 0.3053311793214863
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
Hi HN, I'm Jonathan. My co-founder, Thomas, and I started building Mistle in Feb.We saw larger tech companies like Ramp (Inspect) and Stripe (Minions) build this internally and thought an open source version should exist.We made a few very intentional decisions when working on this:1. Credentials are kept out of the sandbox. Authorized access goes through a proxy, so agents do not directly receive credentials.2. The harness is not our problem. We're not going to tackle things like memory, self-learning.3. No magic. Configurations are explicit. You can bring your own keys for models, sandboxes, and other providers. You can write your own instructions and agent.Mistle can be run locally with a single command: https://github.com/mistlehq/mistle#run-mistle-locallyQuestions, feedback and ideas are welcome!
Enrichment
- Theme
- developer tools for AI agents
- Vertical
- Horizontal
- Function
- Model & infra
- Audience
- Developer
- AI stance
- AI-native
- Project type
- Hobby / open-source project
- Normalized one-liner
- infrastructure for sandboxed coding agents
- Manually corrected
- False
Could you build this?
No Running untrusted agent code securely requires microVM virtualization, hardened sandbox networking, kernel-level isolation, and secure secret proxying that cannot be reliably vibe-coded.
What it would actually take: A production platform uses lightweight microVMs (like Firecracker or gVisor) orchestrating container lifetimes in milliseconds via Rust or Go. The system needs specialized network sandboxing (eBPF or iptables isolation) to enforce egress filtering and an out-of-band proxy that injects credentials dynamically into HTTP/API calls without exposing keys to the agent execution environment. This demands deep systems programming, Linux kernel security, and virtualization expertise.
Discussion
No comments on this launch.
Competitors
Other products that read as similar to this one — 310 launches clear the similarity bar, closest 8 shown.
Attention rank: #240 of 311 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 189 days after the earliest competitor.
- 143.dev · hn · 2026-06-30 · 13 upvotes · similarity 0.54
- Agent Vault · hn · 2026-04-22 · 156 upvotes · similarity 0.50
- Run Agent Skills with mistral.rs v0.8.10: /v1/skills support and more · hn · 2026-06-18 · 20 upvotes · similarity 0.48
- Era · hn · 2025-11-27 · 62 upvotes · similarity 0.48
- Run AI coding agents in real, local sandboxes, not Git worktrees · hn · 2026-04-12 · 6 upvotes · similarity 0.47
- How to build and self-host a code review agent · hn · 2026-07-31 · 29 upvotes · similarity 0.47
- Buda · ph · 2026-05-01 · 197 upvotes · similarity 0.46
- I'm running parallel Pi agents on a local sandbox · hn · 2026-05-03 · 8 upvotes · similarity 0.45
Other launches for this product
Same idea, different domain
Nobody's really built a model & infra tool for Fintech yet.