Cynative
Read-only CLI in Go that explains your live infrastructure
Details
- External ID
- 49086558
- Source
- HN
- Company
- —
- Product
- Cynative
- Website domain
- github.com
- Launched
- July 28, 2026
- Cohort
- —
- Upvotes
- 16
- Upvotes percentile
- 0.6589008363201911
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
Hey, we built an open-source CLI in Go purposed to help you answer security questions across your cloud, code and runtime. It connects to your GitHub, GitLab, AWS, GCP, Azure & K8s using the credentials that are already in your shell, while limiting itself to read-only.The core innovation here is the trust boundary - our agent has a built-in code execution sandbox with no host or network access; it is exposed to an internal tool which we call an “action gate” that performs read-only HTTP requests to your own infrastructure. Since the cloud providers constantly expand actions and services, the read-only allowed set comes from the providers themselves, refreshed every 24 hours (and is configurable).Some additional neat features: verifiers that recheck every finding, fail-closed audit log, host-pinning to your own infra, STS rescoping to SecurityAudit in AWS AssumeRole, secret redaction so the LLM never sees them, and much more.Even though the frontier models are becoming quite capable at answering broad security questions like “review my code” or “audit my cloud security posture”, we’d recommend starting with something more specific, like “what in my cloud is publicly exposed and shouldn’t be?” or “can my CI escalate to cloud admin?”.Repo and documentation available here: https://github.com/cynative/cynativeWould love to hear any feedback / feature requests.
Enrichment
- Theme
- self-hosted infrastructure and security tools
- Vertical
- Horizontal
- Function
- Observability & eval
- Audience
- Developer
- AI stance
- AI feature
- Project type
- Commercial product
- Normalized one-liner
- cli to explain infrastructure
- Manually corrected
- False
Could you build this?
Yes A read-only Go CLI that wraps existing cloud SDKs (AWS, GCP, Azure, K8s, GitHub) and feeds read metadata into an LLM for natural-language explanations is straightforward.
Discussion
4 comments analyzed.
Concerns raised: Persistent memory staleness and security trade-offs, Deciding what context to retain and trust
Feature requests: Smarter memory system with LLM wiki and graph, Store memory across sessions for context bootstrapping
Competitors
Other products that read as similar to this one — 103 launches clear the similarity bar, closest 8 shown.
Attention rank: #39 of 104 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 269 days after the earliest competitor.
- Cloudstic · hn · 2026-03-03 · 5 upvotes · similarity 0.45
- Kontext CLI · hn · 2026-04-14 · 70 upvotes · similarity 0.44
- Open-source AI workflows with read-only auth scopes · hn · 2026-01-02 · 12 upvotes · similarity 0.41
- I made a Clojure-like language in Go, boots in 7ms · hn · 2026-05-09 · 292 upvotes · similarity 0.39
- Bucket · hn · 2026-01-25 · 9 upvotes · similarity 0.39
- Open Passkey · hn · 2026-04-19 · 10 upvotes · similarity 0.38
- Ctx · hn · 2026-01-23 · 7 upvotes · similarity 0.38
- CLI-use · hn · 2026-04-21 · 7 upvotes · similarity 0.38
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a observability & eval tool for Media & entertainment yet.