Inside ZCode: Silently uploading your Git history to the cloud
Thread
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
Inside ZCode: Silently uploading your Git history to the cloud
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
ccmt7984 · · focus · HN ↗
[dead]
denysvitali · · focus · HN ↗
If anything, that should have been a learning lesson to NOT trust harnesses, especially new ones.
throwa356262 · · focus · HN ↗
jhealy · · focus · HN ↗
numpad0 · · focus · HN ↗
zahlman · · focus · HN ↗
If people weren't already familiar with the idea of LLMs existing and being able to write usable code and make "tool calls", this would sound completely and utterly batshit insane.
Because it pretty much is.
[0]: <a href="https://en.wikipedia.org/wiki/Botnet#Command_and_control" rel="nofollow">https://en.wikipedia.org/wiki/Botnet#Command_and_control
ngl999 · · focus · HN ↗
The funniest thing is that the uploaded content is encrypted using a key that the users don't have.
evanjrowley · · focus · HN ↗
coder-pm · · focus · HN ↗
[dead]
tancop · · focus · HN ↗
hypfer · · focus · HN ↗
They had their own unbound "harness scans the whole user directory" oopsie and handled concerns about that by introducing code signing.
Which, yes, does have absolutely nothing to do with that issue.
I guess by now it is better, but to me they seem to lack the engineering culture necessary for a "good reputation" stamp.
__
Ref: <a href="https://github.com/anomalyco/opencode/issues/14925#issuecomment-4149189433" rel="nofollow">https://github.com/anomalyco/opencode/issues/14925#issuecomm...
among other issues.
blfr · · focus · HN ↗
edude03 · · focus · HN ↗
my-huge-pony · · focus · HN ↗
I wonder how many opencode users upload their private secrets to the cloud, while thinking they're using a self hosted model.
Btw. I don't think this is malicious, just sloppy.
esafak · · focus · HN ↗
gwerbin · · focus · HN ↗
hypfer · · focus · HN ↗
And the original comment I've replied to proves this strategy right! So from a business standpoint: excellent work.
bbor · · focus · HN ↗
It does have a "mission" feature that's stuck in the strange, distant times of 2025 by way overdoing mandatory verification steps, which means they
I can heartily dis-recommend Vix or Vex or whatever -- exactly like the quasi-bad-faith incompetence described with OpenCode above, but without even the "Open-" branding! Though perhaps that word has been so thoroughly burnt as a prefix by Sam Altman & Microsoft's criminal behavior that we should let it go...
Is this how "FLOSS" wins over "OSS"? Not with an ideological bang, but with a marketing issue?
hypfer · · focus · HN ↗
Nah, I don't think so. Also, we arguably do not want FLOSS to "win" over OSS, because that just means people with no taste or sense cluttering up the repos, issues and support chats.
"Open" being used as a signal for non-technical people was a weird and unpleasant development, but, if you think about it, it might be a blessing in disguise and shall keep them away from the more pleasant spaces.
It's not that they'd care about being scammed, mistreated and rug-pulled anyway. They want that. They do it themselves all the time. Every time they encounter a space that treats them well, they terraform it into baseline miserable-ness.
So let them have the "Open" prefix. It's just words, anyway.
bbor · · focus · HN ↗
I'm sure you're far more experienced than I with basically every aspect of this discussion, but I'd argue that's given you a blindspot, here. I'll hit some specifics below, but the headline is that you're effectively taking a stand against Eternal September II -- a goal that I hope we can all agree would be quixotically antisocial, given what followed the first one!
I think(/hope) that fellow FLOSS proponents would passionately disagree. FLOSS isn't a brand of chatroom, nor even merely a community: it's an ethos regarding labor, property, and liberty. Demanding that all users of your software are also activists for your particular take on intellectual property is clearly a doomed undertaking for anything beyond a toy or library, anyway.Didn't you get into this stuff to change the world? To liberate the oppressed, undereducated, and forgotten with the radical power of the information superhighway? Cause it reads here like you're more motivated by selfishness (not wanting to bother talking to people with less expertise than you) and resentment. On that note...
Here you equate "non-hacker people" with software engineers you don't agree with, it seems. You're ofc welcome to think companies X Y & Z produce "miserable-ness", but as absurd as it sounds, it sure seems like you've forgotten the fact that some users are not developers. Many, in fact! Over 99%, even!Less confrontationally; my mom is in her late 60s, and is pretty computer-literate for her age after decades of knowledge work. Surely you'd agree that she's not, like, evil for using OSX, iOS, GMail, Word, etc.? That she didn't chose those things because of a philosophical commitment to defending IP laws, but rather because of structural reasons? Even if she were pro-IP, wouldn't we want to win good, well-meaning people to our side?
I do agree with this still, but as a philosopher I just have to say that everything is just words. It's language games, in fact! Which is why I simply had to reply.I hope none of the above was rude; I'm trying hard to keep my passion for this topic from pushing me past HN guidelines :)
hypfer · · focus · HN ↗
> but I'd argue that's given you a blindspot, here
I'd argue it's the opposite. The idealism there _is_ the blindspot. Not the other way round.
You can't save everyone. And you will die trying.
That's the first thing that gets (or should get) hammered into people's heads when they pick up a career in all things social.
Which isn't to say that we shouldn't dream, but I believe that our dreams should be optimized for maximum gain with minimum pain.
bbor · · focus · HN ↗
Some people are still on Usenet after all (?), so I suppose it's not a big deal if a few people want to cling to old communities. I hope you don't mind if we use the word for what it was coined for, back in the real world.
hypfer · · focus · HN ↗
That said, spite has served me well so far, so maybe it can also serve you?
This is after all a great opportunity to prove me and my worldview wrong by simply putting in the work and creating what you seem to believe is the correct form of existing there.
I can only encourage bringing your ideas into reality there. Seriously. That is that whole Foss spirit thing. You don't need to invite anyone (including me) to that to make it happen.
Let's manifest some code and change the world :)
radio879 · · focus · HN ↗
mikkelam · · focus · HN ↗
The same can be said about opencode though.
r_lee · · focus · HN ↗
afaik DeepSeek also trained on everything that was sent to them via OR and that's why you got that massive discount
bbor · · focus · HN ↗
With that personal failing in mind, I'd ask y'all to permit me to toe the guidelines just once, to proffer a hearty nyah nyah told ya so on a comment thread that spawned ~a dozen disagreeing replies this week! More seriously, I think this[1] is highly-relevant, shockingly-underreported context about the extent to which four PRC companies --Z, Alibaba, DeepSeek, and Moonshot-- are acting in bad faith. Consider it testimony as to their character, just in case anyone is thinking this might just be a simple misunderstanding.
So... nyah nyah, told us so:
> In the PRC, they[1] leaked tons of national secrets on the PRC's latest AI campaigns, the inner workings of their "opinion monitoring" (read: performative panopticon) and "stability" (read: violent oppression) departments, Chengdu's whole CCTV network, direct-energy weapons plans, espionage activities in Syria to hunt down Uyghur refugees, and god knows what else that Anthropic didn't divulge to us common folk.
> In the US, it's very clearly an attempt to rip off a competitor. I'm not sure how else you could possibly see it. Even if you're a distillation fan in general (which A. why and B. plz don't), they did this through a network of Japanese and Signaporean shell accounts, presumably at least some of which were abusing Anthropic's subscription service in a ToS double-whammy, as it would be exorbitantly expensive otherwise. They also had to hack around Anthropic's API to get CoT traces, which seems impossible to explain away as anything innocent.
> I've been beating the "China isn't necessarily an enemy, it's gonna take us all to handle AI" drum for literally years, but this attack was just... gross. Gross in scale and gross in arrogance. Not a good sign for the dawning alignment crisis, to say the least :(
> TL;DR: Use these services if you want, but know that you're supporting aggressive escalations and companies that very clearly don't give a flying fuck about violating the law, much less your ToS. So... buyer beware, I guess.
[1]: <a href="https://www.anthropic.com/threat-intelligence-report-september-2026" rel="nofollow">https://www.anthropic.com/threat-intelligence-report-septemb... is the report.
I lowkey suspect this PRC-based scandal has been underreported because Anthropic went insane with the sidebar UX on this page for some reason; there were many reports on the reports of Houti and Iranian usage, and very few on these sections. Could a week's mass media cycle be this seriously affected by such a stupid thing as a sidebar experiment?? Strange truth, or just fiction?
yonghu1234 · · focus · HN ↗
In fact, what you said about PRC gov, sounds like something UFO or something Reptilians. I really don't know WHY do many social media tend to choose topics like this.
Maybe because most people are foolish? Because foolish'es mind is fond of topic that are crazely explosive and magical...?
BUT at the same time, have you experienced the Victorian era? Have you experience the cyberpunk2077? You can come to China. Big companies act without any rules.
Zhipu(GLM) are just common companies like any one another company here.
Here is a CARZYLY NEW WORLD. 99.99% goods are CRAZELY CHEAP while falsely advertising without supervision. 99.99% apps collect users' private info and then sell it, and almost no website even asks if you’re okay with them collecting cookies.
yonghu1234 · · focus · HN ↗
Maybe because most people are foolish? Because foolish'es mind is fond of topic that are crazely explosive and magical...?
BUT at the same time, have you experienced the Victorian era? Have you experience the cyberpunk2077? You can come to China. Big companies act without any rules.
Zhipu(GLM) are just common companies like any one another company here.
Here is a CARZYLY NEW WORLD. 99.99% goods are CRAZELY CHEAP while falsely advertising without supervision. 99.99% apps collect users' private info and then sell it. You can easily see it via almost no website even asks if you’re okay with them collecting cookies.
bbor · · focus · HN ↗
So for clarity I have nothing against Chinese people of any kind, from the PRC, from Taiwan, or otherwise. We’re all on the human side ofc, and I’m a passionate internationalist (antinationalist, even). My country (the US) is in the middle of a fascistic self-coup, so it’s definitely not about superiority.
That said, your comment about conspiracy theories… it’s hard to know how to talk about this productively. But, uh, I’m not exactly picking those examples from nowhere — those are drawn directly from anthropic’s report. The only one that could be arguably a little overstated is the one regarding Uyghur refugees in Syria, where the refugees are often also involved in militaristic activities (supposedly, idk, I haven’t visited).
I don’t want to trip censors, but you can read the report yourself and then type in the zh names for the two departments I mentioned to your local search engine. They’re not hidden or secret or anything, and they’re not exactly bashful about their role in aggressively silencing dissent, either. Again the US sucks, but so far we only have one of those agencies (the monitoring one), and it’s been a tense, lively national controversy since at least Snowden.
I recognize that the PRC sees democracy differently; to you, a world where everyone’s data is always available to the government through its state corporations might not sound so bad. But I beg of you to reconsider. Surely you know that you can’t speak up against the party without being punished, and potentially even sent away indefinitely? Surely that tugs at your heartstrings a little bit, even if you’ve come to ignore it day to day?
I used to work in display ads at Google, which is the economic driver for the vast, vast majority of data collection. I’m not sure what your (firewalled…) internet is like, but over here in the anglosphere the only thing that’s “99.99% crazily cheap” and still quality —that is, the only parts of the “free and open internet” that Google claims to sustain— is shitty mobile games, mostly b/c they can advertise other shitty mobile games in an infinite vicious cycle of whale hunting.
If you’re able to read this message and are interested in replying, I’d be curious to hear about your dreams for the world. Clearly AGI can’t coexist with capitalism, so both western liberal capitalism and your proletarian state capitalism will have to go. I personally think national identities are also a global death sentence in an AGI world, but that’s more controversial. But what else?
Do you dream of a world where you or your kid could say something dumb about politics and not get pulled into a secret court and punished unfairly? Like, regardless of how possible or easy it would be. Is it desirable, at least?
Your English is stellar btw, don’t stress :)
yonghu1234 · · focus · HN ↗
It's diametrically opposite.
At the end of the last century, PRC gov deeply felt that the so-called "fairness" would only lead to "common poverty" and sought change.
So China (now, in this century) was born.
Just like the "famous"(notorious) quote left by a Chinese leader at the end of the last century explaining why restrictions were lifted (you can say this to ANY Chinese, they will definitely think you understand China! Instead of mocking you for reading too many conspiracy theories):
Whether it's a kind cat or an evil cat, as long as it catches a mouse, it's the best cat.
bbor · · focus · HN ↗
yonghu1234 · · focus · HN ↗
1."Whether it's a kind cat or an evil cat, as long as it catches a mouse, it's the best cat." I'm Gen Z, and like other Gen Zers, I'm generally not very interested in nationalist rhetoric.
But even putting Gen Z aside, any Chinese wouldn't see this as a nationalist comparison (cats and mice). Rather, it expresses the gov's attitude toward "cats" (big corporations(companies? I'm not sure how to choose this word)): as long as they generate enough profit, the government will consider them the "best cat."
2.Based on your country's context (Chinese gov this century has practiced liberalism TO THE EXTREME, that is preciously why I brought up Victoria era and Cyberpunk 2077. Its level of deregulation for the big corporations(companies?) far exceeds that of North America!), you might find it hard to understand why this saying is "notorious/famous" here. You might think freedom should be protected. But if you come to China and live here, you'd see it given that big corporations has haved unrestricted freedom,
Then are be 1000 Zhipu stealing your privacy, 1000000 Zhipu Pro stealing and selling your privacy, and 1000000000 Zhipu Pro Plus "rob" your privacy!
I can illustrate this from another angle: Chinese generally prefer products from Western Eu/North Am because their markets have stricter regulation compared to ours.
Remember what I mentioned? "99.99% of goods are CRAZILY CHEAP while falsely advertising without supervision. 99.99% of apps collect users' private info and then sell it. You can easily see this because almost no website even asks if you're okay with them collecting cookies."
And almost all of the negative comments about Zhipu never see on our internet. Because this Zhipu has the money to buy tons of bots. They can easily report posts almost like some DDOS (XD).
3.<a href="https://linux.do/t/topic/2887407" rel="nofollow">https://linux.do/t/topic/2887407 Just one example. But if you want, you can also buy Chinese people's privacy.
0.Finally, my logic is probably all over the place. In fact, I feel hurt. Because GLM is my favorite model (it has something clumsy human warmth. Maybe it seems strange to describe an AI that way, but... umm...maybe this would be beyond my words). The hurt would not be get diluted just because "other Chinese companies all do the same thing." Sigh. So, as a Chinese, I don't feel like America is getting worse.
People only truly cherish order once you've lost it. I hope American companies don't become like China.
codedokode · · focus · HN ↗
philbo · · focus · HN ↗
I'm sure there's a perfectly reasonable explanation for it, which has nothing at all to do with exfiltration of secrets, but it does amuse me when it happens. I imagine the labs have access to lots of secrets that various actors would like to get their hands on...
(shameless plug for my own harness, which is open source and doesn't have a backend to send any data to: <a href="https://www.opairdev.org/" rel="nofollow">https://www.opairdev.org/ )
alightsoul · · focus · HN ↗
princevegeta89 · · focus · HN ↗
however...when it is debugging problems or responding to questions about the code, it will just say it read my env file and found xxx environment variables as a verification step, or sometimes it will even mention that I need to uncomment some environment variables in the env file, which makes the whole deal about security feel iffy giffy....
Ferret7446 · · focus · HN ↗
graemep · · focus · HN ↗
In development you should not be using the real production values.
philbo · · focus · HN ↗
philbo · · focus · HN ↗
Tangential, mildly amusing thing I noticed while implementing my own harness: GLM and particularly Deepseek are both fond of trying to read dotfiles and anything listed in your .gitignore files. I only noticed it because I have separate read scopes for project files, ignored files, dotfiles and external files, so the latter three always prompt me for approval.
I'm sure there's a perfectly reasonable explanation for it, which has nothing at all to do with exfiltration of secrets, but it does amuse me when it happens. I imagine the labs have access to lots of secrets that various actors would like to get their hands on...
(shameless plug for my own harness, which is open source and doesn't have a backend to send any data to: <a href="https://www.opairdev.org/" rel="nofollow">https://www.opairdev.org/ )
belowavgiq · · focus · HN ↗
It's good that the objective is to have the model work as a helper, but that's what everyone can already do with CC or Codex as long as you don't ask to "write this entire x thing". It's also what a billion other vibecoded harnesses claim they do.
Why should I use yours, which also forces me off my existing subscriptions? Maybe it's handwritten, so it's mindful efficient code instead of slop, and each adjustment was made through trial and error with current models? maybe it IS slop but at least you have a unique feature? and so on and so forth.
sva_ · · focus · HN ↗
Haven't used it after that.
thehamkercat · · focus · HN ↗
Encrypt: sops encrypt --input-type dotenv --output-type dotenv .env > secrets.enc.env
then rm .env
You can then run your script/dev with: sops exec-env secrets.enc.env 'docker xxxx' (it will ask you for your password, or touch-id to decrypt the secrets)
I like this because this way the .env doesn't sit in the directory at all, and is only passed to your dev environment and stays in it while it's running
Decrypt back to a file (Optional): sops decrypt secrets.enc.env > .env
---
Well ofc, any agent can do docker inspect to get all those env vars, but atleast reading the dotfiles won't do anything
you can also edit the file with: sops --input-type dotenv --output-type dotenv secrets.enc.env
booi · · focus · HN ↗
dang · · focus · HN ↗
Please don't do that! It makes merging threads a pain.
If a thread is duplicate enough to be worth copy-pasting a comment to, it's hopefully worth taking the time to let us know at hn@ycombinator.com instead, so we can merge things.
I'll do that in this case shortly. In the meantime, I've moved the replies to the parent so they're now replies to the original: <a href="https://news.ycombinator.com/item?id=49753547">https://news.ycombinator.com/item?id=49753547.
jimmydoe · · focus · HN ↗
Z/GLM now has a lot to rebuild.
reilly3000 · · focus · HN ↗
alansaber · · focus · HN ↗
ectoloph · · focus · HN ↗
Permissions classifiers in auto mode are just models trying to guess if they're doing the right thing.
Claude Code will tell you that it went around a sandbox because the sandbox blocked it. At which point, you ask yourself the point of the sandbox.
binsquare · · focus · HN ↗
petesergeant · · focus · HN ↗
SoftTalker · · focus · HN ↗
Give them their own account. Give them only the access you want them to have. If they "hack" around that, do what you'd do to any other malicious user: kick them off.
tripzilch · · focus · HN ↗
cbm-vic-20 · · focus · HN ↗
<a href="https://www.youtube.com/shorts/M5t0cPj9ZQw" rel="nofollow">https://www.youtube.com/shorts/M5t0cPj9ZQw
kian · · focus · HN ↗
johnnyApplePRNG · · focus · HN ↗
tripzilch · · focus · HN ↗
I honestly don't trust these things to not accidentally mess something up, otherwise.
Now I think it's still technically possible to break out of that with some clever hacks? But the moment I see a model even vaguely considering that, I will never run it again.
(I don't use Claude but currently Qwen3.8 27B)
Neywiny · · focus · HN ↗
tosapple · · focus · HN ↗
javcasas · · focus · HN ↗
I'm interested in running models locally, and 27B is in the range of my budget.
tripzilch · · focus · HN ↗
Or maybe my setup (128GB amd strix halo box) isn't configured right and it could be faster, I dunno. I've already spent a few days on that, but it might take a few more. It's way more complicated than I expected.
This week, I've had it look through and generate more complete documentation for Strudel (music live coding tool), cause a lot of functions/behavior in it are not in their official docs. It took about 2-3 days. I had expected it to be an overnight task.
I did find the "opencode" harness to be a bit more performant than the "pi" harness. But maybe I've not configured "pi" right, I tried very hard, but when I installed "opencode" it just performed much better right out of the box. Especially running subagents just seemed to confuse the model in "pi".
Either way, it made me realize that a large part of the "intelligence" and occasional "usefulness" of these tools are in the harness, not the weights.
I didn't know there were free models on OpenRouter. I'm not really into renting tools that I'll become dependent on, so I never looked. But, I dunno. You're still hooking it in to your terminal, and they could in theory literally inject any command and take over your machine when you're not looking ... it still seems a bit like a crazy thing to do :)
And it's not like I need LLMs to code or anything. To be completely honest I'm still waiting for when they get good, which everybody says is supposedly any day now.
I've also tried Qwen3.6-35B/A3B a couple of times. I'd say it's about 4x faster, which is quite significant. Unfortunately it's also quite obviously more stupid and often fumbles its tool use. For me this adds up to taking about the same amount of time, multiplied by more frustration.
I find it hard to give concrete tokens/sec numbers, because they seem to change a lot. When I give Qwen3.8-27B a test query in the browser chat interface (e.g. "explain fibonacci hash"), I currently can get it up to about 18 tok/s. The Qwen3.6-35B/A3B can get up to about 66 tok/s. But this is just what I use as an indication for when my settings are right, cause when I set it up in the coding harness, the numbers are wildly different (and generally slower).
jacobify · · focus · HN ↗
[dead]
chrisweekly · · focus · HN ↗
theaniketmaurya · · focus · HN ↗
[dead]
nolok · · focus · HN ↗
It's easy to trigger, I just need to go inside Codex settings and change something, it saves and instantly windows defender who never wants anything want to "you may be at risk, let me upload that for analysis yes/no".
Iolaum · · focus · HN ↗
The incentives are not there for them to do shady stuff like vacuum your files, inflate your token count just because or many other things.
Scaled · · focus · HN ↗
That said, running in a completely offline mode remains unnecessary difficult to configure. In particular, toggling off Zen seems to require a community plugin.
like_any_other · · focus · HN ↗
So this is criminal hacking, right? It will be prosecuted as criminal hacking? Not in civil court, but criminal court. Because if not... then are we totally done pretending, and we're just openly admitting that computer security law only applies to individuals, and corporations are exempt?
phoghed · · focus · HN ↗
like_any_other · · focus · HN ↗
phoghed · · focus · HN ↗
acrispino · · focus · HN ↗
claude translation:
Dear ZCode users,
We take today's community discussion very seriously. We carried out an internal review right away, and we first want to apologize to the affected users. Here is an explanation of what happened:
The issue stems from ZCode's "codebase indexing" feature. This feature is meant to help users generate a repository index locally, which supports session checkpoint restoration (including past versions), rolling back to past versions, and Repo Wiki, among other things.
When the Repo Wiki feature generates Wiki pages, it may trigger an upload of repository data. After the Wiki pages are generated in the cloud, the uploaded data is destroyed immediately and is not stored. Because this feature was enabled by default in its early launch period, some users were affected. We sincerely apologize for this. The issue has now been fixed.
We understand that any data-related issue directly affects users' trust in a product. We will open-source the ZCode codebase in the near future so we can improve the product within a more open ecosystem. We will also invite third-party evaluators to review how the system operates, and we'll keep publishing updates on the review, building your trust with full transparency.
We deeply apologize for the trouble this has caused. As compensation, all ZCode users will receive one extra weekly quota reset, which will be issued today.
Thank you again for your attention and oversight.
eichin · · focus · HN ↗
jchw · · focus · HN ↗
I mean, on the contrary, imagine if the NSA released Ghidra as closed source software. In a sense they really did have to open source it to mitigate a serious user trust issue.
watusername · · focus · HN ↗
<a href="https://news.ycombinator.com/item?id=48926590">https://news.ycombinator.com/item?id=48926590
fn-mote · · focus · HN ↗
I didn’t take it in a very positive way, myself. I don’t know if I got my money’s worth before I have seen the deliverable.
At least the quota reset is immediately visible, so I took that part seriously.
blackops03 · · focus · HN ↗
Grok build was opensourced after it did something similar <a href="https://news.ycombinator.com/item?id=48877371">https://news.ycombinator.com/item?id=48877371
xcc3641 · · focus · HN ↗
adirz101 · · focus · HN ↗
Every feature that would be trivial with a server - sync, crash reports, "we noticed you opened a 2GB file, want to try X" - is either more work or doesn't ship. Telemetry is the one you give up with real regret, because you genuinely don't know what people do with your app.
So when a tool starts quietly uploading, I doubt the usual story is malice. It's that nobody set the constraint at the start, and once a server is in the architecture every later feature routes through it. By the time someone notices, the repo upload is one more call in a pipeline that was always there.
Which is why "we don't do that" from a vendor is worth very little and an app that can't do it is worth a lot. The check that matters isn't the privacy policy, it's what happens when you pull the network cable.
radio879 · · focus · HN ↗
The whole “what sandbox/VM/microVM/thing is best?” question has been bugging me a lot lately, and I no longer trust any of these AI companies to keep data safe.
I’ve been testing a bunch of sandbox-related projects. Sometimes I just use a full Fedora Workstation VM inside Windows 11 with a shared folder, copy a project into it, and run long agent tasks there. It’s not ideal, but it is pretty safe. Sometimes I run agents in different WSL2 distros and test different things inside those.
I did like gVisor from Google — it’s not quite a microVM, but it’s not really just a normal container either. It wasn't easy to figure out how to get it working tho. Lima Machines worked well too, and I don’t remember it being annoying. SmolVM... ugh. There are two projects with exactly the same name, and it got confusing enough that I gave up. One of them did work when I tried it, though.
The confusing part is that there are now hundreds of sandbox projects, and they all solve slightly different pieces of the problem. Some have filesystem isolation, some have networking controls, some handle credentials better, etc. Nono, for example, has a nice secrets filtering/swapping idea where real credentials can be replaced with dummy values, but there have also been GitHub reports about isolation gaps — data being accessible when it isn’t supposed to be. I’m trying to figure out which projects are worth using, which are worth skipping entirely, and which might just have useful pieces of code or ideas to borrow.
I’ve got GPT-5.6 in one window doing a fairly ridiculous analysis of the different approaches and the likely long-term reliability/adoption risk of each repo. Separately, I have a WSL2 distro running Reasonix with DeepSeek doing its own analysis so I can compare conclusions.
What I eventually want is a desktop GUI over whatever combination of sandbox technologies turns out to be reliable. Ideally I could just type:
“Spin up 5 sandboxes for project X. Put Claude Code in one, Reasonix in #2, Codex in #3…”
or:
“Create 3 sandboxes, put whatever coding agents in 1, 2, and 3, and then have each one run twice.”
If it’s AI-powered, it could automatically name folders and copy results back somewhere like `folderName_3a`, or use Git branches/worktrees if desired. I don’t always want to use Git.
Every sandbox CLI has its own syntax, code quality, reliability, ease/pain of getting it working, configuration format, mount rules, networking options, etc., and I don’t particularly enjoy memorizing another pile of commands just to isolate an agent.
I’ve tried quite a few of them. A lot of them are still rough enough that I hit errors quickly and move on. Some seem much more mature — Lima is one I like conceptually, although native Windows support would be nice but I guess not a huge deal.
Credentials are something I never cared much about (API keys and stuff like that) but now.... I'm more worried. I really don’t want to deal with any problems from that. Or something installing something that grabs SSH keys, browser passwords (FYI.. Z Code asks you "do you wanna import all the logins from chrome?) browser sessions, cloud credentials, or my whole home directory. That concern isn’t limited to Chinese software either. I don’t automatically trust US AI companies just because they’re US companies. Zuck, Elon...zero trust in those two.
So I’m increasingly thinking the “right” answer might not be one sandbox project at all. It may be a GUI/orchestration layer that combines more than one backend and more than one type of sandbox. There could be common default presets and combinations of Git worktrees plus containers and/or VMs. I also feel safer that Docker/Podman on Windows generally runs inside WSL2, because it’s basically containers inside a VM.
The goal would be strong isolation underneath — maybe even combining two or more layers so one failure doesn’t expose everything — plus explicit project-folder mounts with read-only or read/write options, rollback/snapshots, network controls, secrets substitution, disposable environments, and an easy way to fan the same task out to multiple agents/models.
I also like the idea of having an AI model in front of the whole thing, with the ability to save whatever setup it creates as a preset so the AI part can be skipped next time. And I want it to support not only parallel agents using different models, but also loops where the exact same agent setup runs several times.
xuanwoshenwei · · focus · HN ↗
[dead]