Running an AI coding agent shouldn’t mean handing it your whole machine.
This is a dev post classified by Jev as AI dev tools (a tool drop), kept by the Dev Radar because it carries real work, not commentary.
Running an AI coding agent shouldn’t mean handing it your whole machine. Clampdown is a hardened container sandbox for running AI coding agents against a project directory. It helps you limit what an agent can access by restricting its filesystem to the working directory, using an explicit network allowlist, and keeping real API keys in a separate proxy container. Key features: • Kernel-level filesystem rules – Landlock policies are applied before the agent binary starts • API key isolation – the agent receives a dummy key while an auth proxy holds the real credentials • Network controls –
Posted by Dan Kornas (99.1k followers) 1 h ago · 3 likes · 637 views · view the original post on X. Kept by the Dev Radar as AI dev tools.
More dev work like this
- One day after Laya and 4 after Jev, @cognition releases Kev another open model that… — @plotarmordev
- I'm "claude project" pilled. — @rileybrown
- UI bugs are hard to explain. This tool turns them into agent-ready evidence. — @DanKornas
- executor v2 was slow so I sent this prompt to Astra and then went out for a walk — @RhysSullivan
- GPT-6 Astra and Claude Fable 5.2 hit a 5,384-task bloodbath and every AI founder is… — @marfinxx
- Grok Build v1.0.39 is out with a few practical updates. Standouts include subagents can… — @blankspeaker
- I've been trying to explain something to a few people this week, and I want to just put… — @volatilemarkts
- Finding the right agent tool shouldn’t mean digging through random GitHub topics. — @DanKornas
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 17k posts from 4.9k X accounts over the last 21 days, 1.9k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-20 23:42 UTC. Full method.