HNHacker News
TopNewBestAskShowJobs

SegmentTree

12 karma · joined May 8, 2025

submissionscomments
SegmentTree··on Coop – Isolated VM Environments for Running Claude Code and Codex
Yes, that's how I am using it. However there is an experimental qemu microvm backend and a push for podman support if that is more interesting for you.
SegmentTree··on Coop – Isolated VM Environments for Running Claude Code and Codex
Personally I am using Eclipse Enclave to sandbox my agents. Good to see another fully open source solution in Coop.
SegmentTree··on Ask HN: Who is using MCP in production?
We use MCP when security and tight capability boundaries are important.

For example, even GitHub’s fine-grained tokens aren’t always fine-grained enough for our use cases. In those situations, it’s straightforward to build a small MCP server that exposes exactly the operations we want an agent to have access to.

That gives us a much smaller and more explicit attack surface, without having to manually audit every possible GitHub CLI invocation the agent might make.

SegmentTree··on Docker Sandboxes – Disposable, isolated sandboxes for AI agents
Eclipse Enclave does exactly that: There is an outbound firewall and secret injections, so that the agent never sees a real key. And it's fully open source: https://github.com/eclipse-enclave/enclave
SegmentTree··on Humans missed 1 in 3 threats approving AI agent commands across 40k game runs
As soon as I tried Claude Code it was clear to me that I want it to run in yolo mode, but safely. I can very much recommend the Eclipse Enclave sandbox which is fully open source, see https://github.com/eclipse-enclave/enclave
SegmentTree··on Humans missed 1 in 3 threats approving AI agent commands across 40k game runs
I agree. I am using Eclipse Enclave with great success to sandbox my agents https://github.com/eclipse-enclave/enclave
SegmentTree··on A GitHub Issue Title Compromised 4k Developer Machines
Isn't the main vulnerability the cache poisoning in GitHub Actions?

Yes, the agent installed a malicious package in its workflow. But if GitHub Actions had been properly isolated, the attack would not have been possible.

It's basically impossible to protect against malicious injections when consuming unknown inputs. So the safeguard is to prevent agents from doing harm when consuming such inputs. In this case, it seems nothing would have happened if GitHub Actions itself had not been vulnerable.

SegmentTree··on Show HN: Built a desktop app to organize photos locally with duplicate detection
Thanks for the showcase.

I have a question: Can your tool detect duplicates with lower resolution? A typical use case would be images received via chat apps, which are often downscaled to save bandwidth. If I have a higher quality version, I'd like to keep only the larger one.

SegmentTree··on Void: Open-source Cursor alternative
I think it's worth mentioning that the Theia IDE is a fully open source VS Code-compatible IDE (not a fork of VS Code) that's actively adding AI features with a focus on transparency and hackability.