2026-10-11 16:37 UTC

Submilli's released runtime executes agent-generated TypeScript in WebAssembly and enforces semantic, argument-level permissions declared in YAML Blueprints (e.g., 'Allow a refund up to $500, only for customer 123') outside the model's control, and becomes an adopted containment layer for code-writing agents if developers deploy it in production agentic workflows; quiet fade closes it as another Show HN release.

state: seedheat: lowuncertainty: mediumconvergesscott: mediumagentic-security agent-sandboxing code-execution agent-permissionssomdoron

What is this?

Submilli is a newly released runtime for 'business agents that generate code': agent-written TypeScript executes inside a WebAssembly sandbox while a 'semantic permission model' β€” declarative YAML Blueprints with argument-level rules like 'allow a refund up to $500, only for customer 123' β€” is enforced outside the model's control, letting agents act rather than only draft. It surfaced via a Show HN launch attributed to developer 'somdoron'; the supplied web results contain no independent coverage of the product, its author, or any adoption, so the containment and permission-enforcement claims rest entirely on the project's own launch materials. What the results do establish is the surrounding territory: Wasm-as-agent-sandbox is an actively argued pattern (a Wasm I/O 2026 talk calling it the strongest sandbox for agent runtimes, plus multiple sandbox frameworks like wasm_af and Wasmtime-based agent stacks), and teams currently cap agents at actions 'cheap to get wrong' with humans reviewing every output β€” the exact ceiling a runtime-enforced semantic permission layer claims to lift. Whether Submilli specifically breaks out or fades as another Show HN release is not resolvable from this material.

Why it matters to Scott

An indie Show HN developer independently shipped, as a Wasm runtime with YAML Blueprints, the position Scott's canon argues: semantic argument-level permissions ('refund ≀ $500, only for customer 123') enforced outside the model on agent-generated code β€” his Autonomy Budget, Manners-vs-Physics, and SiloOS deterministic capability-checked exits landing in someone else's product, at the exact intersection of Code-First Architecture and containment (governing code the agent wrote, not just tool calls). Worth inspecting for SiloOS's capability-definition layer and bankable as a dated receipt, but launch-level traction with no independent coverage keeps it evidence-to-watch, not a verdict β€” hence medium, not high.
ip:concept.runtime-containmentip:framework.siloosip:concept.manners-vs-physicsip:concept.autonomy-budgetip:framework.code-first-architecturedev:project.silo-osradar:concept.agent-sandboxingradar:concept.policy-enforcementradar:concept.wasmradar:concept.agent-authorizationradar:verb-authority-argument-checksradar:wasmer-local-agent-sandboxes
queries asked of Scott's wikis
  • agent sandboxing and safe code execution in harnesses
  • tool permission enforcement outside the model
  • capability-based security / YAML permission manifests
  • human approval gates for agent actions
  • WebAssembly as agent runtime
  • agent autonomy trust ceiling in business workflows

Measured heat

now 0 pts/hpeak 4 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 120h
points/hour across evidence Β· reading as of 2026-10-12 02:59:37.977291+11:00 Β· deterministic, not a model opinion

How the heat travelled

10-06 17:13 (minted)⭐ origin echo-reconstructed'A code-execution runtime with a semantic permission model, for business agents that generate code' β€” agent-submitted TypeScript runs in Web
Submilli maintainers on github (echo) Β· attributed from hn.story.49980140 Β· published time unknown
β€”
10-06 15:39first on hacker news Β· published Β· lag ?Show HN: Submilli – runtime with semantic permissions for agents that write code
somdoron
β€”
10-06 15:39amplified on hacker news πŸ‘‘hn.story.49980140
somdoron
peak 3 Β· 1 comments Β· 98% of case engagement
10-06 16:25our radar first saw it Β· lag ?discovery anchor: hn.story.49980140β€”
pace: p37 vs 1247 stories at the 96h mark (now 120h old) β€” ahead of agentgate-signed-agent-receipts (1.3x), behind acs-local-skill-risk-catalog (0.8x)

Evidence (2) β€” ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnShow HN: Submilli – runtime with semantic permissions for agents that write code
Retrieved article excerpt

Open article Β· Retrieved 2026-10-06T16:42:30.740614+00:00

[Submilli](https://github.com/submilli/submilli-runtime/blob/main/docs-site/public/favicon.svg)

# Submilli

A code-execution runtime with a [semantic permission model](https://submilli.ai/docs/blueprints/#semantic-permission-model), for business agents that
generate code. Think about someone who wants to allow their customer support agent to issue a refund of up to $500 for platinum clients, and up to $100 for all other customer tiers. Currently, there's no elegant way to do this, (that we know of, at least).

They could try to add it as a safeguard to the prompt, but due to the nature of models, it will likely only work *some* of the time. By using the Submilli Runtime to execute the agent generated code, the owner of that agentic workflow can define these guardrails in advance, and they will be enforced by the runtime, outside the model's control.

[Docs](https://submilli.ai/docs/) Β·
[Set up with your agent](https://submilli.ai/docs/quickstart/#agent-setup) Β·
[Quickstart](https://submilli.ai/docs/quickstart) Β·
[Roadmap](https://github.com/submilli/submilli-runtime/blob/main/ROADMAP.md) Β·
[Discord](https://discord.gg/VphpukeGGj) Β·
[Website](https://submilli.ai)

[CI](https://github.com/submilli/submilli-runtime/actions/workflows/ci.yml)
[Release](https://github.com/submilli/submilli-runtime/releases)
[Container image](https://github.com/submilli/submilli-runtime/pkgs/container/submilli-runtime)
[Helm chart](https://github.com/submilli/submilli-runtime/pkgs/container/charts%2Fsubmilli)
[License: Apache 2.0](https://github.com/submilli/submilli-runtime/blob/main/LICENSE)
[Docs](https://submilli.ai/docs/)
[Discord](https://discord.gg/VphpukeGGj)

---

Code mode and programmatic tool calling started a movement toward agents
that write code, instead of calling tools one by one. There are many reasons for that movement and its growinf popularity - you can read more about it [here](https://submilli.ai/docs/why/#video-code-execution-introduction).

We built Submilli to be the runtime for those agents. The agent submits TypeScript code,
and the Submilli runtime executes it in WebAssembly for isolation. We rebuilt
the runtime completely, so there is no `node:http` or `node:fs`. It is a new
runtime, built purposely for agents.

Submilli comes with governance, but from the inside out. Before any call to
the outside world, the Submilli runtime first checks the environment's permissions (the
Blueprint) to see if the call is allowed. It doesn't just check the IP,
domain, or port. The Package author defines a semantic language for each
operation, and that language allows you to control what your agent can do in those terms: "Allow a
refund up to $500, only for customer 123".

We also gave the ecosystem a reset. All the Packages for Submilli are written
from scratch, purposely for agents, with [semantic permissions](https://submilli.ai/docs/blueprints/#semantic-permission-model). We don't use npm
Packages, and while we do support MCP servers, Packages are the native way to
work with Submilli.

## What a rule looks like

Blueprints are one of Submilli's main building blocks, together with
Packages. A Blueprint defines the environment the agent's code runs in. You
write it in YAML.

The permissions block in a Blueprint defines what the code can do, and you
fill it by adding capabilities. Package authors publish the capabilities the package supports, and you
grant them (or some of them) to the agent by declaring them in the Blueprint.

You may also define variables for a Blueprint, which is a very powerful concept. Now you control not only the
agent's capabilities, but also the context it can use them in. In the example
below, we allow the code to access billing operations, bot only for a specific customer (that is bound to the runtime by the host application), and to issue credits of up to $500. If the agent tries a different customer, or a higher amount, the operation fails.

```
variables:
  customerId:
    required: true

permissions:
  main:
  - capability: acme.com/charges.list
    filter: customerId == ${vars.customerId}
    action: allow
  - capability: acme.com/credits.apply
    filter: customerId == ${vars.customerId} and amount <= 50000  # cents
    action: allow
```

## Install

macOS and Linux:

```
curl -fsSL https://submilli.ai/install.sh | sh
```

Windows (PowerShell):

```
irm https://submilli.ai/install.ps1 | iex
```

This installs the `submilli` CLI and `submilli-server`. To run the server in
production, use [Docker Compose](https://submilli.ai/docs/server/deploy-with-compose),
the [Helm chart](https://submilli.ai/docs/server/deploy-on-kubernetes), or
[systemd](https://submilli.ai/docs/server/deploy-on-linux).

## Connect your agent

Submilli keeps your harness. Your agent gets tools to run programs, over MCP
or HTTP. There are tutorials for
[LangChain Deep Agents](https://submilli.ai/docs/tutorials/connect-deepagents),
[Mastra](https://submilli.ai/docs/tutorials/connect-mastra),
the [OpenAI Agents SDK](https://submilli.ai/docs/tutorials/connect-openai-agents),
the [Claude Agent SDK](https://submilli.ai/docs/tutorials/connect-claude-agent-sdk),
and [plain HTTP](https://submilli.ai/docs/tutorials/use-the-http-api).

## Features

- [Blueprints](https://submilli.ai/docs/blueprints) with rules on an operation's
  arguments, bound per session, and everything denied by default.
- [Packages](https://submilli.ai/docs/packages) that wrap your APIs and hold the
  credentials, so generated code never sees a secret. Curated Packages for
  GitHub, Slack, Gmail, Google Drive and Calendar, Linear, Notion, Sentry, and
  web search are [included](https://github.com/submilli/submilli-runtime/blob/main/packages/README.md).
- [Limits](https://submilli.ai/docs/server/set-limits) on memory, time,
  stack depth, model tokens and more. A failing run ends alone, and the rest of the
  server keeps serving.
- An [audit trail](https://submilli.ai/docs/reference/audit-trail) of every
  refusal, run, session, and admin change.
- MCP servers as Packages, with rules on their tools.
- Checks for Package authors: `--deny-warnings` in CI and an
  [agent security review](https://submilli.ai/docs/packages/review-package-security).
- HTTPS, API tokens with admin and user roles, and an encrypted secret store.

Missing an integration? [Request a curated Package](https://github.com/submilli/submilli-runtime/issues/new?template=curated-package.yml).

## Status

Submilli is young and moving quickly. Releases are on the
[releases page](https://github.com/submilli/submilli-runtime/releases).
Breaking changes are called out in the release notes, and a Blueprint that
uses a removed feature fails to load with a message that says what to write
instead.

Our short term roadmap is published [here](https://github.com/submilli/submilli-runtime/blob/main/ROADMAP.md). If you have ideas, suggestions, requests or questions, we'd love to chat.

Submilli is open source. If you’re thinking of using it, we’d love to talk to you! Contact us at [email protected].

## Repository

| Path | What it holds |
| --- | --- |
| `crates/` | The compiler, runtime, CLI, and server, in Rust |
| `packages/` | The curated Packages |
| `charts/` | The Helm chart |
| `docs/`, `docs-site/` | The book at [submilli.ai/docs](https://submilli.ai/docs/) |
| `skills/` | The skill that teaches coding assistants to write Blueprints and Packages |
| `examples/` | The quickstart and harness examples |

## Contributing

Read [CONTRIBUTING.md](https://github.com/submilli/submilli-runtime/blob/main/CONTRIBUTING.md) first. Contributions need the
[CLA](https://github.com/submilli/submilli-runtime/blob/main/CLA.md). Report security issues as described in
[SECURITY.md](https://github.com/submilli/submilli-runtime/blob/main/SECURITY.md), not in public issues. Questions are welcome on
[Discord](https://discord.gg/VphpukeGGj).

## License

[Apache License 2.0](https://github.com/submilli/submilli-runtime/blob/main/LICENSE).
somdoron31
🟧 echo.github ⭐'A code-execution runtime with a semantic permission model, for business agents that generate code' β€” agent-submitted TypeScript runs in WebSubmilli maintainersβ€”β€”

Interpretation history

Decision trace