Open Source Radar — September 30: the infrastructure under agents

Share
Open Source Radar — September 30: the infrastructure under agents

The signal today is not another model release — it is the layer beneath the agents: where they run, what they are allowed to reach, and what they already know how to do.

NVIDIA OpenShell (Rust, Apache-2.0, ~11,000 stars) — NVIDIA's answer to the question every team running autonomous agents eventually asks out loud: what can this thing actually touch? OpenShell gives each agent a sandbox that starts with almost no outbound network access, then opens specific holes through a proxy that checks the method and path of every request, so file access, credentials and data exfiltration are contained by policy instead of by hoping the model behaves. The sandbox image already carries the common coding agents alongside Python, Node and the usual shell tools, which means you can put an existing agent inside it rather than rewrite it. It is still alpha — the 0.1.0 milestone is open and the Kubernetes path is labelled experimental — so this is a runtime to evaluate, not to standardise on yet. The upside is the obvious one: it is the difference between an agent holding your keys and an agent that has to ask for them.


dbx (Rust, Apache-2.0, ~22,700 stars) — A database client that fits in about 25 MB and reaches 90-plus engines, from Postgres, MySQL and SQLite to Redis, MongoDB, ClickHouse and DuckDB, shipped as a desktop app plus a Docker service, a browser build and a CLI. What earns it a slot here is the agent story: a separate MCP server lets a coding agent query the connections you already configured, with permission modes that run from read-only to full access, and an assistant that checks generated SQL for destructive statements before anything executes. It covers the unglamorous essentials too — schema diffs, entity diagrams, execution plans, data transfer between connections, exports to CSV, JSON, Markdown and XLSX. Note that the MCP piece installs separately from the desktop app, and that the write modes are what you want to configure before handing an agent the keys.


reverse-skill (MIT, ~39,000 stars) — A skill pack that stops coding agents improvising when a task turns into reverse engineering. Point Claude Code, Codex, Cursor or OpenCode at an APK, a stripped binary, obfuscated front-end JavaScript or a CTF challenge and it routes the job to a methodology, checks which tools are actually available, then runs a repeatable workflow instead of guessing at commands. The design detail worth copying is the scope gate: an authorisation and network-profile step comes before the agent is allowed near a target, and everything after that lands in an evidence-to-finding timeline plus a field journal, so the reasoning can be audited later. It ships 44 routing rules, 45 skill modules and a 175-case regression benchmark validated on Windows and Ubuntu, and the maintainers even published a security review of their own installer this month. The disclaimer is explicit that this is for authorised testing only — read it that way.


AI Engineering from Scratch (MIT, ~62,000 stars) — The biggest learn-by-building curriculum on GitHub right now: 523 lessons across 20 phases, roughly 342 hours, in Python, TypeScript, Rust and Julia. It belongs on a radar rather than a reading list because every lesson ends in a reusable artifact — a prompt, a skill, an agent or an MCP server — so the output is something you can drop into a project instead of notes you never reopen. The repository reports 114,584 readers and about 182,000 page views in the 30 days to August 29, with landing pages in a dozen languages. It is a course, not a tool, and the star count is doing a lot of marketing work for it; still, for a working developer trying to get from calling APIs to building and evaluating the thing, there is nothing denser.


GitBot (MIT, TypeScript, launched on Product Hunt today) — Turns a job you keep retyping for Claude Code, Codex or OpenCode into a reusable bot: write the instructions once, decide what it may touch, then run it across any repository, with each run kept as a thread you can return to. It runs on your own machine with the agent logins you already have, asks for no account and collects no telemetry, and bots can be exported or imported from a shared library — the bundled ShipGuard example reads a branch and returns merge or block with file-and-line evidence. Two honest caveats: it is days old and tiny, and its local web console has no authentication, so keep it on a trusted network. Watch it rather than build a workflow on it.

Worth watching this week: whether the sandbox runtimes and the skill packs converge, because an agent that is contained by policy and told which method to follow is a much easier thing to sign off on.

Which of these would you let near your production credentials, and what would you need to see first? Tell us in the comments.

Sources: NVIDIA OpenShell (GitHub) · dbx (GitHub) · reverse-skill (GitHub) · AI Engineering from Scratch (GitHub) · GitBot (GitHub)

Read more

Akhetonics says its all-optical CPU reaches a customer in 2026

Akhetonics says its all-optical CPU reaches a customer in 2026

Light-based computing keeps promising more than it delivers — but one Munich startup has just put a date on its bet, and the interview laying it out is doing the rounds on Hacker News this week. Akhetonics says it will deploy its first commercial machine with a major customer by the end of 2026, with several more planned for 2027. The company, founded by Michael Kissner and Leonardo Del Bino, is building a computer where data enters as light, is switched as light, and circulates through memory

The Week in AI — October 5–11, 2026

The Week in AI — October 5–11, 2026

Every big claim this week turned out to rest on fine print more interesting than the headline: revenue only the company reporting it can define, safety tests sandboxed while the product keeps the web, and a Pentagon phase-out nobody would confirm until reporters kept asking. The week's top 5 1. OpenAI's revenue was $20 billion below the numbers everyone quoted — and the gap was definitional. The Financial Times reported Thursday that OpenAI's annualized revenue runs roughly $20 billion unde

Drone strike shuts a third Yandex data center, taking YandexGPT offline

Drone strike shuts a third Yandex data center, taking YandexGPT offline

Russia's largest tech company is learning what the AI era's infrastructure war looks like from the receiving end — three data centers in four days, and with them much of the cloud layer Russian businesses run on. A Ukrainian drone strike knocked out Yandex's data center in Vladimir early Sunday morning, the third of the company's facilities hit since October 8. The site — reported at roughly 50 MW and designed for about 2,880 server racks — stopped operating completely after the attack, Yandex

Agent teams cost up to 5x more, barely score higher

Agent teams cost up to 5x more, barely score higher

The multi-agent hype train hit a benchmark this weekend — and the grid and the trucking regulators had quiet weeks of their own. Vals AI put agent teams head-to-head with single agents on its Vibe Code Bench, and the teams cost between 1.8 and 5.1 times more for almost no extra quality. The evals company ran GPT-6 Sol and Claude Opus 5.5 solo and in teams across 50 apps at two reasoning efforts; out of four comparisons, only one was statistically significant — Sol at medium effort, where the t