# Show HN: Submilli – runtime with semantic permissions for agents that write code

> Source: <https://github.com/submilli/submilli-runtime>
> Published: 2026-10-06 15:39:33+00:00

A code-execution runtime with a [semantic permission model](https://submilli.ai/docs/blueprints/#semantic-permission-model), for business agents that
generate code. Think about someone who wants to allow their customer support agent to issue a refund of up to $500 for platinum clients, and up to $100 for all other customer tiers. Currently, there's no elegant way to do this, (that we know of, at least).

They could try to add it as a safeguard to the prompt, but due to the nature of models, it will likely only work *some* of the time. By using the Submilli Runtime to execute the agent generated code, the owner of that agentic workflow can define these guardrails in advance, and they will be enforced by the runtime, outside the model's control.

[Docs](https://submilli.ai/docs/) ·
[Set up with your agent](https://submilli.ai/docs/quickstart/#agent-setup) ·
[Quickstart](https://submilli.ai/docs/quickstart) ·
[Roadmap](https://github.com/submilli/submilli-runtime/blob/main/ROADMAP.md) ·
[Discord](https://discord.gg/VphpukeGGj) ·
[Website](https://submilli.ai)

Code mode and programmatic tool calling started a movement toward agents
that write code, instead of calling tools one by one. There are many reasons for that movement and its growinf popularity - you can read more about it [here](https://submilli.ai/docs/why/#video-code-execution-introduction).

We built Submilli to be the runtime for those agents. The agent submits TypeScript code,
and the Submilli runtime executes it in WebAssembly for isolation. We rebuilt
the runtime completely, so there is no `node:http` or `node:fs`. It is a new
runtime, built purposely for agents.

Submilli comes with governance, but from the inside out. Before any call to the outside world, the Submilli runtime first checks the environment's permissions (the Blueprint) to see if the call is allowed. It doesn't just check the IP, domain, or port. The Package author defines a semantic language for each operation, and that language allows you to control what your agent can do in those terms: "Allow a refund up to $500, only for customer 123".

We also gave the ecosystem a reset. All the Packages for Submilli are written
from scratch, purposely for agents, with [semantic permissions](https://submilli.ai/docs/blueprints/#semantic-permission-model). We don't use npm
Packages, and while we do support MCP servers, Packages are the native way to
work with Submilli.

Blueprints are one of Submilli's main building blocks, together with Packages. A Blueprint defines the environment the agent's code runs in. You write it in YAML.

The permissions block in a Blueprint defines what the code can do, and you fill it by adding capabilities. Package authors publish the capabilities the package supports, and you grant them (or some of them) to the agent by declaring them in the Blueprint.

You may also define variables for a Blueprint, which is a very powerful concept. Now you control not only the agent's capabilities, but also the context it can use them in. In the example below, we allow the code to access billing operations, bot only for a specific customer (that is bound to the runtime by the host application), and to issue credits of up to $500. If the agent tries a different customer, or a higher amount, the operation fails.

```
variables:
  customerId:
    required: true

permissions:
  main:
  - capability: acme.com/charges.list
    filter: customerId == ${vars.customerId}
    action: allow
  - capability: acme.com/credits.apply
    filter: customerId == ${vars.customerId} and amount <= 50000  # cents
    action: allow
```

macOS and Linux:

```
curl -fsSL https://submilli.ai/install.sh | sh
```

Windows (PowerShell):

```
irm https://submilli.ai/install.ps1 | iex
```

This installs the `submilli` CLI and `submilli-server`. To run the server in
production, use [Docker Compose](https://submilli.ai/docs/server/deploy-with-compose),
the [Helm chart](https://submilli.ai/docs/server/deploy-on-kubernetes), or
[systemd](https://submilli.ai/docs/server/deploy-on-linux).

Submilli keeps your harness. Your agent gets tools to run programs, over MCP
or HTTP. There are tutorials for
[LangChain Deep Agents](https://submilli.ai/docs/tutorials/connect-deepagents),
[Mastra](https://submilli.ai/docs/tutorials/connect-mastra),
the [OpenAI Agents SDK](https://submilli.ai/docs/tutorials/connect-openai-agents),
the [Claude Agent SDK](https://submilli.ai/docs/tutorials/connect-claude-agent-sdk),
and [plain HTTP](https://submilli.ai/docs/tutorials/use-the-http-api).

- [Blueprints](https://submilli.ai/docs/blueprints) with rules on an operation's
arguments, bound per session, and everything denied by default.
- [Packages](https://submilli.ai/docs/packages) that wrap your APIs and hold the
credentials, so generated code never sees a secret. Curated Packages for
GitHub, Slack, Gmail, Google Drive and Calendar, Linear, Notion, Sentry, and
web search are[included](https://github.com/submilli/submilli-runtime/blob/main/packages/README.md) .
- [Limits](https://submilli.ai/docs/server/set-limits) on memory, time,
stack depth, model tokens and more. A failing run ends alone, and the rest of the
server keeps serving.
- An [audit trail](https://submilli.ai/docs/reference/audit-trail) of every
refusal, run, session, and admin change.
- MCP servers as Packages, with rules on their tools.
- Checks for Package authors: `--deny-warnings` in CI and an[agent security review](https://submilli.ai/docs/packages/review-package-security) .
- HTTPS, API tokens with admin and user roles, and an encrypted secret store.

Missing an integration? [Request a curated Package](https://github.com/submilli/submilli-runtime/issues/new?template=curated-package.yml).

Submilli is young and moving quickly. Releases are on the
[releases page](https://github.com/submilli/submilli-runtime/releases).
Breaking changes are called out in the release notes, and a Blueprint that
uses a removed feature fails to load with a message that says what to write
instead.

Our short term roadmap is published [here](https://github.com/submilli/submilli-runtime/blob/main/ROADMAP.md). If you have ideas, suggestions, requests or questions, we'd love to chat.

Submilli is open source. If you’re thinking of using it, we’d love to talk to you! Contact us at [hello@submilli.ai](mailto:hello@submilli.ai).

| Path | What it holds | 
|---|---|
| `crates/` | The compiler, runtime, CLI, and server, in Rust | 
| `packages/` | The curated Packages | 
| `charts/` | The Helm chart | 
| `docs/` ,`docs-site/` | The book at [submilli.ai/docs](https://submilli.ai/docs/) | 
| `skills/` | The skill that teaches coding assistants to write Blueprints and Packages | 
| `examples/` | The quickstart and harness examples | 

Read [CONTRIBUTING.md](https://github.com/submilli/submilli-runtime/blob/main/CONTRIBUTING.md) first. Contributions need the
[CLA](https://github.com/submilli/submilli-runtime/blob/main/CLA.md). Report security issues as described in
[SECURITY.md](https://github.com/submilli/submilli-runtime/blob/main/SECURITY.md), not in public issues. Questions are welcome on
[Discord](https://discord.gg/VphpukeGGj).
