cd /news/ai-agents/show-hn-submilli-runtime-with-semant… · home › topics › ai-agents › article
[ARTICLE · art-146155] src=github.com ↗ pub= topic=ai-agents verified=true sentiment=↑ positive

Show HN: Submilli – runtime with semantic permissions for agents that write code

Submilli launched a code-execution runtime that enforces semantic permissions on agent-generated TypeScript code, executing it in WebAssembly and checking each outbound call against a YAML-defined Blueprint before allowing it. The runtime lets operators set rules such as allowing a refund of up to $500 only for a specific customer ID, with the guardrails enforced outside the model's control rather than in the prompt. Submilli ships its own Packages written from scratch with semantic permissions, supports MCP servers, and installs via a curl script on macOS and Linux or PowerShell on Windows, with Docker Compose, Helm, and systemd deployment options for the server.

read4 min views1 publishedOct 6, 2026
Show HN: Submilli – runtime with semantic permissions for agents that write code
Image: Michielbdejong (auto-discovered)

A code-execution runtime with a semantic permission model, for business agents that generate code. Think about someone who wants to allow their customer support agent to issue a refund of up to $500 for platinum clients, and up to $100 for all other customer tiers. Currently, there's no elegant way to do this, (that we know of, at least).

They could try to add it as a safeguard to the prompt, but due to the nature of models, it will likely only work some of the time. By using the Submilli Runtime to execute the agent generated code, the owner of that agentic workflow can define these guardrails in advance, and they will be enforced by the runtime, outside the model's control.

Docs · Set up with your agent · Quickstart · Roadmap · Discord · Website

Code mode and programmatic tool calling started a movement toward agents that write code, instead of calling tools one by one. There are many reasons for that movement and its growinf popularity - you can read more about it here.

We built Submilli to be the runtime for those agents. The agent submits TypeScript code, and the Submilli runtime executes it in WebAssembly for isolation. We rebuilt the runtime completely, so there is no node:http or node:fs. It is a new runtime, built purposely for agents.

Submilli comes with governance, but from the inside out. Before any call to the outside world, the Submilli runtime first checks the environment's permissions (the Blueprint) to see if the call is allowed. It doesn't just check the IP, domain, or port. The Package author defines a semantic language for each operation, and that language allows you to control what your agent can do in those terms: "Allow a refund up to $500, only for customer 123".

We also gave the ecosystem a reset. All the Packages for Submilli are written from scratch, purposely for agents, with semantic permissions. We don't use npm Packages, and while we do support MCP servers, Packages are the native way to work with Submilli.

Blueprints are one of Submilli's main building blocks, together with Packages. A Blueprint defines the environment the agent's code runs in. You write it in YAML.

The permissions block in a Blueprint defines what the code can do, and you fill it by adding capabilities. Package authors publish the capabilities the package supports, and you grant them (or some of them) to the agent by declaring them in the Blueprint.

You may also define variables for a Blueprint, which is a very powerful concept. Now you control not only the agent's capabilities, but also the context it can use them in. In the example below, we allow the code to access billing operations, bot only for a specific customer (that is bound to the runtime by the host application), and to issue credits of up to $500. If the agent tries a different customer, or a higher amount, the operation fails.

variables:
  customerId:
    required: true

permissions:
  main:
  - capability: acme.com/charges.list
    filter: customerId == ${vars.customerId}
    action: allow
  - capability: acme.com/credits.apply
    filter: customerId == ${vars.customerId} and amount <= 50000  # cents
    action: allow

macOS and Linux:

curl -fsSL https://submilli.ai/install.sh | sh

Windows (PowerShell):

irm https://submilli.ai/install.ps1 | iex

This installs the submilli CLI and submilli-server. To run the server in production, use Docker Compose, the Helm chart, or systemd.

Submilli keeps your harness. Your agent gets tools to run programs, over MCP or HTTP. There are tutorials for LangChain Deep Agents, Mastra, the OpenAI Agents SDK, the Claude Agent SDK, and plain HTTP.

  • Blueprints with rules on an operation's arguments, bound per session, and everything denied by default.
  • Packages that wrap your APIs and hold the credentials, so generated code never sees a secret. Curated Packages for GitHub, Slack, Gmail, Google Drive and Calendar, Linear, Notion, Sentry, and web search areincluded .
  • Limits on memory, time, stack depth, model tokens and more. A failing run ends alone, and the rest of the server keeps serving.
  • An audit trail of every refusal, run, session, and admin change.
  • MCP servers as Packages, with rules on their tools.
  • Checks for Package authors: --deny-warnings in CI and anagent security review .
  • HTTPS, API tokens with admin and user roles, and an encrypted secret store.

Missing an integration? Request a curated Package.

Submilli is young and moving quickly. Releases are on the releases page. Breaking changes are called out in the release notes, and a Blueprint that uses a removed feature fails to load with a message that says what to write instead.

Our short term roadmap is published here. If you have ideas, suggestions, requests or questions, we'd love to chat.

Submilli is open source. If you’re thinking of using it, we’d love to talk to you! Contact us at hello@submilli.ai.

Path What it holds
crates/ The compiler, runtime, CLI, and server, in Rust
packages/ The curated Packages
charts/ The Helm chart
docs/ ,docs-site/ The book at submilli.ai/docs
skills/ The skill that teaches coding assistants to write Blueprints and Packages
examples/ The quickstart and harness examples

Read CONTRIBUTING.md first. Contributions need the CLA. Report security issues as described in SECURITY.md, not in public issues. Questions are welcome on Discord.

── more in #ai-agents 4 stories · sorted by recency
── more on @submilli 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/show-hn-submilli-run…] indexed:0 read:4min 2026-10-06 · —