Your model writes the code. This runs it where it can't touch your machine.
1 comment
realexweb2 days ago
I created this tool because I kept running code that an LLM just wrote in my home folder. That felt risky.
Every time you run a command it happens in its container. The container runs without network access by default. It's rootless. Once the command finishes the container gets deleted. It cleans up after itself.
It uses Linux namespaces, cgroups and seccomp. Not a microVM. It is lightweight and fast.
Read the full thread on Hacker News →
Related stories
- Lobsters · 86 points · about 1 year ago
- Hacker News · 8 points · 6 days ago
- Hacker News · 4 points · about 4 hours ago
- Hacker News · 1 points · 2 days ago
- Hacker News · 2 points · 7 days ago
- Hacker News · 14 points · 8 days ago