01
Edition
07
picks
# AI Hacker Daily — 2026-08-20 The approval click lost, so the agent is being handed its own computer.
# AI Hacker Daily — 2026-08-20 The approval click lost, so the agent is being handed its own computer. This newsletter has spent three weeks measuring the click and the numbers are in: 409,000 real approval decisions graded at **66.3%** accuracy (08-07), Anthropic's own figure that users approve **97%** of permission prompts (08-10), and yesterday's cold-clone reproduction of an agent guardrail that detects 74% of attacks and blocks 8%, where an operator who rubber-stamps everything scores `effective_asr_approve` **1.00** — the exact security of having installed nothing. The industry has evidently reached the same conclusion, because six projects crossed the pool today that all make the same bet: stop asking the human, put the agent in a box, and keep the tape. The timing is not subtle. OpenRouter announced yesterday that it is joining Stripe — the model marketplace moving **10+ trillion tokens a day** across 400+ models for 10 million developers, acquired by a payments company, which is roughly the market declaring model access a billing problem rather than a technical one. On the same morning, HN put 274 points on a Claude Code issue asking it to read a competitor's config file: `AGENTS.md`, filed 2025-08-21, **6,276 reactions**, 371 comments, closed as completed three days ago and still being argued about today by people who do not think it was. So the model is a commodity you buy through a payment rail and the config is a shared file everyone is converging on. What is left to build is the box the thing runs in, and today's picks are ordered by how far that box sits from the machine in front of you — starting with a log on your own laptop and ending with the tool that attacks all five. One warning before the list: containment is not an answer to the question a commenter asked the best-funded project here and never got a reply to, which is what happens when the agent is tricked into doing something it *is* allowed to do.
02
OpenBot — one container per coworker, and the audit row is written before the action
03
OneCLI — the agent never sees the credential, and the gateway that enforces it has a paid tier
04
Agent Substrate — 250 agents on 8 machines, because agents are mostly idle
05
SAM — once every agent has a computer, they need a network, and this one authenticates every packet
06
AI-Infra-Guard — somebody has to attack the box, and the biggest tool for it wants your star
07
One of these,
every weekday.
Free. Unsubscribe by replying with one word. No tracking pixels in the email.