Show HN: Submilli – runtime with semantic permissions for agents that write code Submilli launched a code-execution runtime that enforces semantic permissions on agent-generated TypeScript code, executing it in WebAssembly and checking each outbound call against a YAML-defined Blueprint before allowing it. The runtime lets operators set rules such as allowing a refund of up to $500 only for a specific customer ID, with the guardrails enforced outside the model's control rather than in the prompt. Submilli ships its own Packages written from scratch with semantic permissions, supports MCP servers, and installs via a curl script on macOS and Linux or PowerShell on Windows, with Docker Compose, Helm, and systemd deployment options for the server. A code-execution runtime with a semantic permission model https://submilli.ai/docs/blueprints/ semantic-permission-model , for business agents that generate code. Think about someone who wants to allow their customer support agent to issue a refund of up to $500 for platinum clients, and up to $100 for all other customer tiers. Currently, there's no elegant way to do this, that we know of, at least . They could try to add it as a safeguard to the prompt, but due to the nature of models, it will likely only work some of the time. By using the Submilli Runtime to execute the agent generated code, the owner of that agentic workflow can define these guardrails in advance, and they will be enforced by the runtime, outside the model's control. Docs https://submilli.ai/docs/ · Set up with your agent https://submilli.ai/docs/quickstart/ agent-setup · Quickstart https://submilli.ai/docs/quickstart · Roadmap https://github.com/submilli/submilli-runtime/blob/main/ROADMAP.md · Discord https://discord.gg/VphpukeGGj · Website https://submilli.ai Code mode and programmatic tool calling started a movement toward agents that write code, instead of calling tools one by one. There are many reasons for that movement and its growinf popularity - you can read more about it here https://submilli.ai/docs/why/ video-code-execution-introduction . We built Submilli to be the runtime for those agents. The agent submits TypeScript code, and the Submilli runtime executes it in WebAssembly for isolation. We rebuilt the runtime completely, so there is no node:http or node:fs . It is a new runtime, built purposely for agents. Submilli comes with governance, but from the inside out. Before any call to the outside world, the Submilli runtime first checks the environment's permissions the Blueprint to see if the call is allowed. It doesn't just check the IP, domain, or port. The Package author defines a semantic language for each operation, and that language allows you to control what your agent can do in those terms: "Allow a refund up to $500, only for customer 123". We also gave the ecosystem a reset. All the Packages for Submilli are written from scratch, purposely for agents, with semantic permissions https://submilli.ai/docs/blueprints/ semantic-permission-model . We don't use npm Packages, and while we do support MCP servers, Packages are the native way to work with Submilli. Blueprints are one of Submilli's main building blocks, together with Packages. A Blueprint defines the environment the agent's code runs in. You write it in YAML. The permissions block in a Blueprint defines what the code can do, and you fill it by adding capabilities. Package authors publish the capabilities the package supports, and you grant them or some of them to the agent by declaring them in the Blueprint. You may also define variables for a Blueprint, which is a very powerful concept. Now you control not only the agent's capabilities, but also the context it can use them in. In the example below, we allow the code to access billing operations, bot only for a specific customer that is bound to the runtime by the host application , and to issue credits of up to $500. If the agent tries a different customer, or a higher amount, the operation fails. variables: customerId: required: true permissions: main: - capability: acme.com/charges.list filter: customerId == ${vars.customerId} action: allow - capability: acme.com/credits.apply filter: customerId == ${vars.customerId} and amount <= 50000 cents action: allow macOS and Linux: curl -fsSL https://submilli.ai/install.sh | sh Windows PowerShell : irm https://submilli.ai/install.ps1 | iex This installs the submilli CLI and submilli-server . To run the server in production, use Docker Compose https://submilli.ai/docs/server/deploy-with-compose , the Helm chart https://submilli.ai/docs/server/deploy-on-kubernetes , or systemd https://submilli.ai/docs/server/deploy-on-linux . Submilli keeps your harness. Your agent gets tools to run programs, over MCP or HTTP. There are tutorials for LangChain Deep Agents https://submilli.ai/docs/tutorials/connect-deepagents , Mastra https://submilli.ai/docs/tutorials/connect-mastra , the OpenAI Agents SDK https://submilli.ai/docs/tutorials/connect-openai-agents , the Claude Agent SDK https://submilli.ai/docs/tutorials/connect-claude-agent-sdk , and plain HTTP https://submilli.ai/docs/tutorials/use-the-http-api . - Blueprints https://submilli.ai/docs/blueprints with rules on an operation's arguments, bound per session, and everything denied by default. - Packages https://submilli.ai/docs/packages that wrap your APIs and hold the credentials, so generated code never sees a secret. Curated Packages for GitHub, Slack, Gmail, Google Drive and Calendar, Linear, Notion, Sentry, and web search are included https://github.com/submilli/submilli-runtime/blob/main/packages/README.md . - Limits https://submilli.ai/docs/server/set-limits on memory, time, stack depth, model tokens and more. A failing run ends alone, and the rest of the server keeps serving. - An audit trail https://submilli.ai/docs/reference/audit-trail of every refusal, run, session, and admin change. - MCP servers as Packages, with rules on their tools. - Checks for Package authors: --deny-warnings in CI and an agent security review https://submilli.ai/docs/packages/review-package-security . - HTTPS, API tokens with admin and user roles, and an encrypted secret store. Missing an integration? Request a curated Package https://github.com/submilli/submilli-runtime/issues/new?template=curated-package.yml . Submilli is young and moving quickly. Releases are on the releases page https://github.com/submilli/submilli-runtime/releases . Breaking changes are called out in the release notes, and a Blueprint that uses a removed feature fails to load with a message that says what to write instead. Our short term roadmap is published here https://github.com/submilli/submilli-runtime/blob/main/ROADMAP.md . If you have ideas, suggestions, requests or questions, we'd love to chat. Submilli is open source. If you’re thinking of using it, we’d love to talk to you Contact us at hello@submilli.ai mailto:hello@submilli.ai . | Path | What it holds | |---|---| | crates/ | The compiler, runtime, CLI, and server, in Rust | | packages/ | The curated Packages | | charts/ | The Helm chart | | docs/ , docs-site/ | The book at submilli.ai/docs https://submilli.ai/docs/ | | skills/ | The skill that teaches coding assistants to write Blueprints and Packages | | examples/ | The quickstart and harness examples | Read CONTRIBUTING.md https://github.com/submilli/submilli-runtime/blob/main/CONTRIBUTING.md first. Contributions need the CLA https://github.com/submilli/submilli-runtime/blob/main/CLA.md . Report security issues as described in SECURITY.md https://github.com/submilli/submilli-runtime/blob/main/SECURITY.md , not in public issues. Questions are welcome on Discord https://discord.gg/VphpukeGGj .