Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Dear User of the Universe (sebastiansastre.co)
    —discuss
  2. Getting out of the way: my robotics crash course (thisismypersonalblog.com)
    —discuss
  3. What makes Lisp difficult to read? (paultm.nl)
    —discuss
  4. Pragmatic Anthropomorphism, Or: How to Talk to an Autocompleting Cricket (lmorchard.com)
    —discuss
  5. Citrix NetScaler PreAuth Command Injection CVE-2026-88771 (watchtowr.com)
    —discuss
  6. Earth's mysterious 'hum' points to the sound of waves crashing across the world (abc.net.au)
    —discuss
  7. The Front Wire, a breaking-news wire built on primary sources (thecompound.tech)
    —discuss
  8. The Code Nobody Reads (addyo.substack.com)
    —discuss
  9. UK government tells staff to stop thanking AI chatbots (tomshardware.com)
    1comments
  10. Using C++17 Std:Optional (cppstories.com)
    —discuss
  11. ProjecturEd: One data structure, many editable views, with an AI assistant (projectured.org)
    1comments
  12. Space Lasers Are About to Get Their First Real Test Generating Energy (wired.com)
    —discuss
  13. Strata: Qwen3.8-Flash-Next (125B Moe) on a 8GB+ Nvidia GPU (github.com/niko1221)
    —discuss
  14. Lawrence McEnerney – The Craft of Writing Effectively (1h 22min) [video] (youtube.com)
    —discuss
  15. Wire mainland DeepSeek into a SE Asia trade chatbot (realitypatch.net)
    —discuss
  16. Show HN: Enterprise Postgres for AI and more, from prototype to production (pgedge.com)
    —discuss
  17. Evade Reddit tracking, keep old.reddit.com layout permanently
    —discuss
  18. Why Juicero's Press Is So Expensive (2017) (bolt.io)
    —discuss
  19. Show HN: Online RTSP camera simulator for testing AI vision or VMS (illucam.com)
    —discuss
  20. Cory Doctorow says Hugging Face attack was just "a Python loop and a chatbot" (pluralistic.net)
    1comments
  21. Freelance Developer Pricing: The Framework That Stops the $11/HR Slide (misar.blog)
    —discuss
  22. AI agent startup Instinct raises $1B Series C at $10B valuation (reuters.com)
    —discuss
  23. Viral AI agent Instinct raises $1B Series C at a $10B valuation (techcrunch.com)
    —discuss
  24. Education Miracles [pdf] (columbia.edu)
    —discuss
  25. Work Diary Victory (plover.com)
    —discuss
  26. Show HN: LaunchPact – Get support for your Product Hunt launch (launchpact.io)
    —discuss
  27. Show HN: Free job-market dashboard – which skills and roles postings ask for (payanai.com)
    —discuss
  28. What if automating AI R&D triggers an intelligence explosion? (casp.ac)
    —discuss
  29. Partnership and economic drivers of Gambia men with foreign tourists (nih.gov)
    —discuss
  30. Resurrecting Midway's Ms Gorf – The Arcade Blogger (arcadeblogger.com)
    —discuss

Show HN: OpenAPPA – open-source deterministic guardrails that don't break agents

21 pointsby 1h agoopenappa.com
11 comments
Hi Hacker News! Matvey, one of the authors, is here.

While building enterprise agents, we ran into a problem: the more tools you connect to the AI, the higher the chance it will run out of control and leak sensitive data.

Guardrails, in theory, should prevent this, but the situation is worrying: - Non-deterministic guardrails (LLM as a judge, auto modes, etc.) are vulnerable to prompt injections, or they lack knowledge of the data, making them inefficient (~10% data leaks on our benchmarks). - Existing deterministic guardrails (Cedar, OPA, FIDES, Dogwood) require massive case-specific IF-ELSE-like policies and break agents (~59% utility loss on our benchmarks).

We did something differently.

We’ve taken the best of existing deterministic guardrails and built a policy language that is data-specific, not use-case specific. It lets you scale agents without updating a policy.

On top of that, we’ve added multiple tricks (like a remedy plan or a DualLLM pattern) to help agents operate within those restrictions, raising utility from ~40% to ~90% and making it the first deterministic guardrail that doesn't break agents.

Finally, we’ve designed it to be pluggable into any agent loop with pre- and post-tool-call hooks.

We invite you to check out our benchmarks: https://www.openappa.com/evaluation

Play with it in Claude Code: https://www.openappa.com/claude-code

Try plugging it into your agent: https://www.openappa.com/add-to-agent

Or check the academic paper: https://arxiv.org/abs/2607.24625

We'd love to hear any feedback!

1h agoHN ↗

Finally some determinism in our high-temperature sampling world!

1h agoHN ↗

I still remember the times when ai/ml security was about perturbing pixel gradients to misclassify a panda

1h agoHN ↗

Hi! One of the OpenAPPA authors here. Ask me anything!

My favorite part of APPA is “batteries”: you can run arbitrary programs as part of an authorization decision. For example, a battery could call the GitHub API to check whether a repository is public or private, then use that result to decide whether its contents can be posted to Slack.

1h agoHN ↗

a few days ago I started an agent on gpt-5.6-terra to work on a project, and one of the website pages had a sentence to create GH issues. Agent read it and that was enough to derail and go creating issues with my context

1h agoHN ↗

Guardrails with builtin remediation instead of simply blocking my agent is a mind blowing long awaited experience! Sooo good. Can't recommend more!

1h agoHN ↗

Quick disclaimer, I work at Archestra.

I’ve had the chance to play with OpenAppa for a bit and if there’s one thing that I love with this project: it’s simple to get started with and easy to tweak. imo agentic security shouldn’t have to be painful to setup.

Give it a shot and hopefully ya’ll will find this project useful. It's also open source :)

1h agoHN ↗

i suspect we’ll see more of this: flexible agents but deterministic boundaries. Congrats on launch!

48m agoHN ↗

Really interesting direction. What resonated with me is that you're treating agent security as an information-flow problem rather than a prompt-classification problem. It was not so obvious to me.

A key question I agree isn't just "is this tool call allowed?", but "given everything the agent has read so far, is this information now allowed to flow to this destination?" That feels like a much more fundamental abstraction.

The part I'm particularly curious about is how this will work with policy authoring at scale. What would be the main adoption challenge?

37m agoHN ↗

great question, very practical.

we have a layered answer here: 1) we ship over a dozen "batteries" now (and plan to grow the number) - they contain base annotations for popular services and helper scripts where relevant; 2) we also ship a skill helping you write your own policies for custom services or adopt the default ones based on your specific needs. The criteria "what's acceptable for each particular scenario" varies, there is no "one size fits all" solution; 3) finally, there is a designed placeholder to cover the rest via wildcard AI annotator if needed. The difference between that and regular "auto mode" in coding agents is that APPA's annotator emits local label (e.g. "does this call require a trusted env?"), not wide allow/block, while decision making stays within label algebra.

40m agoHN ↗

the paper is good! thorough. I like it.