{"slug": "show-hn-spens-sandboxed-observable-coding-agents", "title": "Show HN: Spens sandboxed, observable coding agents", "summary": "Spens, a new open-source tool for sandboxing and observing coding agents, launched on Hacker News, using Docker, nono and mitmproxy to create reproducible sandbox environments that capture all agent traffic. Spens supports pi, opencode, claude and codex out of the box with node and python, and its creator notes the Docker-based sandbox is \"good enough\" but can be escaped without gVisor, and that macOS users need OrbStack due to Linux security features unavailable in Docker on Mac.", "body_md": "Spens is a tool created to standardized sandboxing (good enough) and observability around coding agents. It leverages docker, nono and mitmproxy to create a reproducible sandbox environment for agents, that captures all traffic and helps you understand what your coding agent is doing and when. Right now pi, opencode, claude and codex are supported out of the box, with node and python - but you can configure any agent or environment.\n\nIt was created under the realization while working under different repos and agents, that\n\n1. agents do weird stuff sometimes (like try and nuke a folder or poke around your HD) 2. statistics and usage collection is not really consistent (and some like Claude and Codex try and hide info) 3. reproducibility of agents across devices was challenging.\n\nInstead of setting up bespoke environments each time , we needed a way to automate it. And thus Spens was born.\n\nOne note on the security aspect - I write good enough cause it is docker so unless your running something like gVisor it is possible for the agent to escape the sandbox (esp with a loose nono config) - all though in practice I've not seen this behavior.\n\nSecond note - if your on a mac you need orb stack, as the run times take advantage of specific Linux security features that are not available via docker on mac (windows is fine since under the hood, docker leverages wsl)\n\nComments URL: [https://news.ycombinator.com/item?id=49933266](https://news.ycombinator.com/item?id=49933266)\n\nPoints: 1\n\n# Comments: 0", "url": "https://wpnews.pro/news/show-hn-spens-sandboxed-observable-coding-agents", "canonical_source": "https://spens.refwd.ai/", "published_at": "2026-10-02 13:22:13+00:00", "updated_at": "2026-10-02 13:36:25.639049+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "developer-tools", "ai-safety"], "entities": ["Spens", "Docker", "nono", "mitmproxy", "pi", "opencode", "Claude", "Codex"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/show-hn-spens-sandboxed-observable-coding-agents", "markdown": "https://wpnews.pro/news/show-hn-spens-sandboxed-observable-coding-agents.md", "text": "https://wpnews.pro/news/show-hn-spens-sandboxed-observable-coding-agents.txt", "jsonld": "https://wpnews.pro/news/show-hn-spens-sandboxed-observable-coding-agents.jsonld"}}