惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Cloudflare Blog
有赞技术团队
有赞技术团队
H
Help Net Security
V
Visual Studio Blog
F
Fortinet All Blogs
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 司徒正美
G
Google Developers Blog
Google DeepMind News
Google DeepMind News
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Stack Overflow Blog
Stack Overflow Blog
I
InfoQ
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
L
LangChain Blog
N
Netflix TechBlog - Medium
罗磊的独立博客
The GitHub Blog
The GitHub Blog
云风的 BLOG
云风的 BLOG
Hugging Face - Blog
Hugging Face - Blog
A
About on SuperTechFans
aimingoo的专栏
aimingoo的专栏
Recent Announcements
Recent Announcements

Hacker News: Show HN

PurrrrrFocus: Pomodoro Timer App - App Store Workflow Engine — Multi-Step Orchestration for Bun RapidPhoto: Pro Photo Editor App - App Store GitHub - DheerG/swarms: Achieve extraordinary results with claude code across a variety of tasks SPICE simulation → oscilloscope → verification with Claude Code — Lucas Gerads Show HN: VCoding – A 5 MB native Windows IDE with no dynamic dependencies Show HN: LLMs don't hallucinate because they're bad at math, it's the format GitHub - Agent-FM/agentfm-core: AgentFM is a peer-to-peer network that turns everyday computers into a decentralized AI supercomputer. AgentFM lets you run massive AI workloads directly across a global mesh of idle CPUs and GPUs. Show HN: Tracking Top US Science Olympiad Alumni over Last 25 Years GitHub - Potarix/agent-hub: One place to talk to all your agents Show HN: Runtime security for AI agents(injection,tool abuse, data exfiltration) GitHub - dubeyKartikay/lazyspotify: Terminal Spotify client for macOS and Linux GitHub - the-banana-tool/king-louie: Easy to use GUI Personal AI Assistant. Win/Linux/Mac. Show HN I made my vacation rental bookable by AI agents–no Airbnb, 0% commission GitHub - basteez/jsf-autoreload: maven plugin to enable hot reload on jsf projects uvm32/hosts/host-gdbstub at main · ringtailsoftware/uvm32 GitHub - labsai/EDDI: Config-driven engine that turns JSON into production-grade AI agents. Multi-agent orchestration, 12+ LLM providers, MCP/A2A protocols, RAG, persistent memory, and enterprise compliance (EU AI Act, GDPR, HIPAA). Built on Quarkus. GitHub - glitchnsec/fortyone-oss: AI Executive Assistant Platform Quickstart | Alien GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. GitHub - ocrbase-hq/ocrbase: 📄 PDF/IMG ->.MD/JSON Document OCR API for PaddleOCR and GLMOCR. Self-hostable. GitHub - impactjo/home-memory: MCP server that lets your AI assistant remember everything about your home. GitHub - Sets88/dbcls: DbCls is a powerful terminal database client that supports various databases GitHub - neptun2000/heor-agent-mcp GitHub - SeanFDZ/macmind: Single-layer transformer in HyperTalk for the classic Macintosh RollQuation: Math Puzzles - Apps on Google Play GitHub - dropbox/witchcraft Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis GitHub - opentalon/opentalon: OpenTalon is an open-source platform built from the ground up in Go as a robust alternative to OpenClaw LinkedIn™ 职位抓取工具 - Chrome 应用商店
GitHub - chocks/agentctl: agentctl is a focused v1 contro...
chocks · 2026-05-08 · via Hacker News: Show HN

agentctl is a local control plane for coding agents. It gates a small set of risky actions, records a trace for every decision, and can replay prior sessions against a different policy.

Install

go install github.com/chocks/agentctl/cmd/agentctl@latest
agentctl version

agentctl stores all of its state under ~/.agentctl/:

  • policy.yaml
  • traces.jsonl
  • approvals.jsonl

There is no repo-local policy file and no HTTP server.

Quick Start

Attach to a supported agent. attach bootstraps ~/.agentctl/ and writes a default policy if one does not exist yet.

agentctl attach claude-code
# or
agentctl attach codex

Verify the install:

agentctl doctor

Launch the terminal UI:

agentctl ui

Governed Actions

Action What it covers
install_package pip, npm, cargo, go installs
run_code shell execution, script runs
access_secret reading secrets, tokens, credentials
write_file file creation, overwrites, appends
call_external_api outbound HTTP to external services

Everything else stays out of the control path.

CLI

agentctl attach <agent>        Configure agent integration and bootstrap ~/.agentctl/
agentctl detach <agent>        Remove agent integration
agentctl doctor                Check policy, trace store, approvals, and agent status
agentctl gate                  Evaluate one action from stdin
agentctl trace list            Show recent traces
agentctl trace search          Search traces
agentctl replay <session_id>   Re-evaluate a recorded session
agentctl approval list         List approvals
agentctl approval approve <id> Approve a pending escalation
agentctl approval deny <id>    Deny a pending escalation
agentctl ui                    Terminal UI for traces and approvals
agentctl hook claude-code      Claude Code PreToolUse hook adapter
agentctl mcp                   MCP server for Codex and other MCP clients

Policy

agentctl loads exactly one policy file: ~/.agentctl/policy.yaml.

  • Missing file: built-in safe defaults are used.
  • Malformed file: gate, doctor, and mcp fail loudly.
  • Hook mode (agentctl hook claude-code) fails open on malformed policy and writes the error to stderr.

Default policy written by attach:

actions:
  install_package:
    require_hashes: true

  run_code:
    block_patterns:
      - "| bash"
      - "| sh"
      - "| python"
    network: deny

  access_secret:
    require_approval: always
    max_ttl: 300

  write_file:
    block_patterns:
      - ".env"
      - "*.pem"
      - "*.key"

  call_external_api:
    allowed_domains: []

allowed_domains: [] means deny all outbound calls. Omitting allowed_domains means no domain restriction.

Replay

Record a session under a stable session ID:

echo '{"action":"call_external_api","params":{"url":"https://api.openai.com/v1/responses","method":"POST"},"reason":"call provider"}' \
  | agentctl gate --session demo-1

Replay that session against the current global policy:

agentctl replay demo-1

Or replay against an alternate policy file:

agentctl replay demo-1 --policy ./stricter-policy.yaml

Docs

Development

make fmt
make build
make test
make lint

License

MIT. See LICENSE.