{"slug": "show-hn-submilli-runtime-with-semantic-permissions-for-agents-that-write-code", "title": "Show HN: Submilli – runtime with semantic permissions for agents that write code", "summary": "Submilli launched a code-execution runtime that enforces semantic permissions on agent-generated TypeScript code, executing it in WebAssembly and checking each outbound call against a YAML-defined Blueprint before allowing it. The runtime lets operators set rules such as allowing a refund of up to $500 only for a specific customer ID, with the guardrails enforced outside the model's control rather than in the prompt. Submilli ships its own Packages written from scratch with semantic permissions, supports MCP servers, and installs via a curl script on macOS and Linux or PowerShell on Windows, with Docker Compose, Helm, and systemd deployment options for the server.", "body_md": "A code-execution runtime with a [semantic permission model](https://submilli.ai/docs/blueprints/#semantic-permission-model), for business agents that\ngenerate code. Think about someone who wants to allow their customer support agent to issue a refund of up to $500 for platinum clients, and up to $100 for all other customer tiers. Currently, there's no elegant way to do this, (that we know of, at least).\n\nThey could try to add it as a safeguard to the prompt, but due to the nature of models, it will likely only work *some* of the time. By using the Submilli Runtime to execute the agent generated code, the owner of that agentic workflow can define these guardrails in advance, and they will be enforced by the runtime, outside the model's control.\n\n[Docs](https://submilli.ai/docs/) ·\n[Set up with your agent](https://submilli.ai/docs/quickstart/#agent-setup) ·\n[Quickstart](https://submilli.ai/docs/quickstart) ·\n[Roadmap](https://github.com/submilli/submilli-runtime/blob/main/ROADMAP.md) ·\n[Discord](https://discord.gg/VphpukeGGj) ·\n[Website](https://submilli.ai)\n\nCode mode and programmatic tool calling started a movement toward agents\nthat write code, instead of calling tools one by one. There are many reasons for that movement and its growinf popularity - you can read more about it [here](https://submilli.ai/docs/why/#video-code-execution-introduction).\n\nWe built Submilli to be the runtime for those agents. The agent submits TypeScript code,\nand the Submilli runtime executes it in WebAssembly for isolation. We rebuilt\nthe runtime completely, so there is no `node:http` or `node:fs`. It is a new\nruntime, built purposely for agents.\n\nSubmilli comes with governance, but from the inside out. Before any call to the outside world, the Submilli runtime first checks the environment's permissions (the Blueprint) to see if the call is allowed. It doesn't just check the IP, domain, or port. The Package author defines a semantic language for each operation, and that language allows you to control what your agent can do in those terms: \"Allow a refund up to $500, only for customer 123\".\n\nWe also gave the ecosystem a reset. All the Packages for Submilli are written\nfrom scratch, purposely for agents, with [semantic permissions](https://submilli.ai/docs/blueprints/#semantic-permission-model). We don't use npm\nPackages, and while we do support MCP servers, Packages are the native way to\nwork with Submilli.\n\nBlueprints are one of Submilli's main building blocks, together with Packages. A Blueprint defines the environment the agent's code runs in. You write it in YAML.\n\nThe permissions block in a Blueprint defines what the code can do, and you fill it by adding capabilities. Package authors publish the capabilities the package supports, and you grant them (or some of them) to the agent by declaring them in the Blueprint.\n\nYou may also define variables for a Blueprint, which is a very powerful concept. Now you control not only the agent's capabilities, but also the context it can use them in. In the example below, we allow the code to access billing operations, bot only for a specific customer (that is bound to the runtime by the host application), and to issue credits of up to $500. If the agent tries a different customer, or a higher amount, the operation fails.\n\n```\nvariables:\n  customerId:\n    required: true\n\npermissions:\n  main:\n  - capability: acme.com/charges.list\n    filter: customerId == ${vars.customerId}\n    action: allow\n  - capability: acme.com/credits.apply\n    filter: customerId == ${vars.customerId} and amount <= 50000  # cents\n    action: allow\n```\n\nmacOS and Linux:\n\n```\ncurl -fsSL https://submilli.ai/install.sh | sh\n```\n\nWindows (PowerShell):\n\n```\nirm https://submilli.ai/install.ps1 | iex\n```\n\nThis installs the `submilli` CLI and `submilli-server`. To run the server in\nproduction, use [Docker Compose](https://submilli.ai/docs/server/deploy-with-compose),\nthe [Helm chart](https://submilli.ai/docs/server/deploy-on-kubernetes), or\n[systemd](https://submilli.ai/docs/server/deploy-on-linux).\n\nSubmilli keeps your harness. Your agent gets tools to run programs, over MCP\nor HTTP. There are tutorials for\n[LangChain Deep Agents](https://submilli.ai/docs/tutorials/connect-deepagents),\n[Mastra](https://submilli.ai/docs/tutorials/connect-mastra),\nthe [OpenAI Agents SDK](https://submilli.ai/docs/tutorials/connect-openai-agents),\nthe [Claude Agent SDK](https://submilli.ai/docs/tutorials/connect-claude-agent-sdk),\nand [plain HTTP](https://submilli.ai/docs/tutorials/use-the-http-api).\n\n- [Blueprints](https://submilli.ai/docs/blueprints) with rules on an operation's\narguments, bound per session, and everything denied by default.\n- [Packages](https://submilli.ai/docs/packages) that wrap your APIs and hold the\ncredentials, so generated code never sees a secret. Curated Packages for\nGitHub, Slack, Gmail, Google Drive and Calendar, Linear, Notion, Sentry, and\nweb search are[included](https://github.com/submilli/submilli-runtime/blob/main/packages/README.md) .\n- [Limits](https://submilli.ai/docs/server/set-limits) on memory, time,\nstack depth, model tokens and more. A failing run ends alone, and the rest of the\nserver keeps serving.\n- An [audit trail](https://submilli.ai/docs/reference/audit-trail) of every\nrefusal, run, session, and admin change.\n- MCP servers as Packages, with rules on their tools.\n- Checks for Package authors: `--deny-warnings` in CI and an[agent security review](https://submilli.ai/docs/packages/review-package-security) .\n- HTTPS, API tokens with admin and user roles, and an encrypted secret store.\n\nMissing an integration? [Request a curated Package](https://github.com/submilli/submilli-runtime/issues/new?template=curated-package.yml).\n\nSubmilli is young and moving quickly. Releases are on the\n[releases page](https://github.com/submilli/submilli-runtime/releases).\nBreaking changes are called out in the release notes, and a Blueprint that\nuses a removed feature fails to load with a message that says what to write\ninstead.\n\nOur short term roadmap is published [here](https://github.com/submilli/submilli-runtime/blob/main/ROADMAP.md). If you have ideas, suggestions, requests or questions, we'd love to chat.\n\nSubmilli is open source. If you’re thinking of using it, we’d love to talk to you! Contact us at [hello@submilli.ai](mailto:hello@submilli.ai).\n\n| Path | What it holds | \n|---|---|\n| `crates/` | The compiler, runtime, CLI, and server, in Rust | \n| `packages/` | The curated Packages | \n| `charts/` | The Helm chart | \n| `docs/` ,`docs-site/` | The book at [submilli.ai/docs](https://submilli.ai/docs/) | \n| `skills/` | The skill that teaches coding assistants to write Blueprints and Packages | \n| `examples/` | The quickstart and harness examples | \n\nRead [CONTRIBUTING.md](https://github.com/submilli/submilli-runtime/blob/main/CONTRIBUTING.md) first. Contributions need the\n[CLA](https://github.com/submilli/submilli-runtime/blob/main/CLA.md). Report security issues as described in\n[SECURITY.md](https://github.com/submilli/submilli-runtime/blob/main/SECURITY.md), not in public issues. Questions are welcome on\n[Discord](https://discord.gg/VphpukeGGj).", "url": "https://wpnews.pro/news/show-hn-submilli-runtime-with-semantic-permissions-for-agents-that-write-code", "canonical_source": "https://github.com/submilli/submilli-runtime", "published_at": "2026-10-06 15:39:33+00:00", "updated_at": "2026-10-06 15:50:51.598342+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-infrastructure", "developer-tools", "agent-protocols"], "entities": ["Submilli", "Submilli Runtime", "WebAssembly", "MCP", "TypeScript", "npm", "Docker Compose", "Helm"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/show-hn-submilli-runtime-with-semantic-permissions-for-agents-that-write-code", "markdown": "https://wpnews.pro/news/show-hn-submilli-runtime-with-semantic-permissions-for-agents-that-write-code.md", "text": "https://wpnews.pro/news/show-hn-submilli-runtime-with-semantic-permissions-for-agents-that-write-code.txt", "jsonld": "https://wpnews.pro/news/show-hn-submilli-runtime-with-semantic-permissions-for-agents-that-write-code.jsonld"}}