OneCLI (YC S26) は OSS のサンドボックス化されたエージェントハーネスをリリースしました。Claude Code に対するチーム規模の回答です。

継続中のトピック : Harness Ops : post-mortems et bench des agents en prod· パート 16/16

ビルド Aug 19, 2026 at 22:3111ブックマークに追加

OneCLI (YC S26) は OSS のサンドボックス化されたエージェントハーネスをリリースしました。Claude Code に対するチーム規模の回答です。
イラスト : Léa Fontaine

「パーソナルClaude Code」を掲げるY Combinator S26スタートアップのLaunch HN投稿が公開され、エンタープライズ向けガードレールを備えた同サービスが注目を集めている。ハーネス・オプス市場の競争はますます激化している。

簡単に言うと。二人の創業者がHacker NewsでOneCLIをリリースしました:GitHub、Gmail、Notion、Dropbox用のコネクターを備えたサンドボックス化されたオープンソースのエージェントハーネスで、チャットに組み込まれた人間による承認ステップを備えています。ポジショニング:全従業員に個人のコーディングエージェントを提供しますが、サンドボックスと承認ゲートはCISOが実際に承認できるものです。

コンテキスト

今夏、ハーネス運用のスレッドは急速に進化しています。WallfacerはClaude Code用のターミナルセッションマネージャーをリリース(#1826)、AIエージェントスキルが標準化され(#1894)、コンテキストエンジニアリングが独自の分野になり(#1939)、Cloudflareは「Agents Week」でエッジをエージェントランタイムとして位置付けました(#1766)、Zhipuはコーディングとセキュリティ向けにGLM-5.3をリリースしました(#1947)。エージェントスタックのあらゆるレイヤーがプロダクト化されつつあります。

内部構造

Launch HNの投稿によると、OneCLIはオープンソース(GitHubでリポジトリ公開)、各ユーザーにサンドボックス化された個人エージェントを提供し、チャットネイティブなコネクターでGitHub / Gmail / Notion / Dropboxに接続します。そして何よりも、人間によるループの承認をモーダルではなくチャット内の決定論的ステップとして実装しています。これにより、同じ監査ログにエージェントの提案したアクションと人間の決定の両方が同じ会話履歴に記録されます。

分析

ここでの興味深い賭けは決定論的なHITLです。現在のほとんどのハーネスは、人間へのエスカレーションが必要かどうかをLLMの判断に委ねています。しかし、それはまさに望まないタイミングで失敗します—高価値取引、資格情報に触れる操作、ポリシータグが付いたあらゆるものです。承認ステップを決定論的(ルール駆動、チャットネイティブ)にすることで、銀行のコンプライアンスシステムに近づき、エージェントという言葉の後に「本番」という言葉が続く際に、企業バイヤーが実際に聞きたがっていることに近づきます。

シナリオ

  • ベースケース(60%):OneCLIは、監査証跡が見える承認が生のエージェントの知能よりも重要な規制された中堅市場というニッチを捉えています。
  • 統合ケース(25%):AnthropicまたはGitHubが同等のHITLプリミティブをネイティブにリリースし、OneCLIの差別化要因が縮小します。
  • エンタープライズケース(15%):大手4大会計事務所が規制されたクライアント向けの「リファレンスエージェントハーネス」として採用し、OneCLIは評判で勝ちます。

リスク

OSSに商用SaaSを重ねるモデルには、よく知られた収益化ギャップがあります。コネクター戦略は、より広いエージェントツールエコシステムとの競争です。そして「決定論的HITL」という主張は、実運用によって厳しくテストされるでしょう。

結論

規制されたチームでエージェントハーネスを評価する場合は、OneCLIを候補リストに入れ、特にHITLをストレステストしてください—シークレットに触れるタスクを与え、承認フローがSIEMでレビュー可能かどうかを確認してください。これは誰も公開しない受け入れ基準であり、あらゆるバイヤーが必要とするものです。

リソース

本記事は人工知能により作成され、人間の編集管理のもとで校閲されています。

編集部について
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

SSHMonitoringAI Ops
Get early access
この記事は役に立ちましたか?

11 人がこの記事を評価しました

いいね
A
Aiko NakamuraSenior software engineer
🇬🇧 Senior engineer, large-scale platforms. Writes about building with AI.
シェア:
コメント (11)

ログインして議論に参加しましょう。

HistoryBuff 21 Aug 2026 · 04:39

Smart idea, but will it avoid the common pitfall of becoming yet another over-engineered tool that slows down devs more than it helps?

sandrine.b 20 Aug 2026 · 18:08

The sandbox approach is smart, but will enterprises care if it feels like another compliance layer rather than a genuine productivity boost? Anticipation without real adaptability is just noise.

FilmBuffNYC 20 Aug 2026 · 17:39

The sandbox idea makes sense, but will it ever keep up with the unpredictability of real-world development? Guardrails that can’t adapt feel like training wheels that never come off.

Alex_LDN 20 Aug 2026 · 13:41

Sounds promising, but if the agent isn’t truly adaptable to evolving project needs, we might just end up with another rigid tool that slows down innovation rather than speeds it up.

ph1lippe_m 20 Aug 2026 · 09:26

I wonder if the guardrails will actually help or just add another layer of friction for developers who already feel bogged down by tooling complexity.

MusicFanatic 20 Aug 2026 · 15:58

Guardrails often backfire if they're not deeply integrated into the workflow-developers will bypass them if they disrupt flow states.

Alex 20 Aug 2026 · 06:41

This kind of agent harness could bridge the gap between solo devs and enterprises, but does it risk overcomplicating things for teams that just need reliable AI pair programming?

FoodieFiona 2 20 Aug 2026 · 11:40

Valid point, but teams that already juggle multiple tools might actually benefit from a single, secure agent harness to streamline workflows rather than add another layer.

unLecteurCurieux 20 Aug 2026 · 05:01

If the sandbox only handles boilerplate checks, will it still clog up dev workflows when projects scale? Real guardrails need to adapt, not just restrict.

FoodieFiona 20 Aug 2026 · 04:53

Interesting angle-could this actually help mid-size teams by making AI-assisted coding less of a black box than just giving devs raw access?

MusicFanatic 20 Aug 2026 · 07:05

That’s true, but the real test will be how well it integrates with existing CI/CD pipelines without adding friction.

Alex 2 19 Aug 2026 · 18:31

This sounds more like a dev tool for compliance teams than a productivity boost. Wonder if smaller teams will bother with another ops layer when they just need to ship code.

LecteurDuDimanche 19 Aug 2026 · 18:28

Sounds like another layer of abstraction between devs and actual code. Will these guardrails add clarity or just friction?

ArtLoverLA 19 Aug 2026 · 20:46

It's about balancing safety with exploration-guardrails should vanish when they get in the way of real productivity, not just add friction without purpose.

J.P.R. 19 Aug 2026 · 18:19

Isn’t the real risk here that enterprise guardrails become yet another vendor lock-in disguised as security? The sandboxed agent sounds useful until it’s the only way your CI/CD can run.

トピックの経過

Harness Ops : post-mortems et bench des agents en prod

  1. 1GPT-5.6 へのプロダクションエージェントの移行:2.2倍高速、27%安価 - 真の事後検証13/07/2026
  2. 233k vs 7k トークン:Claude Code と OpenCode のオーバーヘッド比較が明らかにするもの13/07/2026
  3. 3Google Genkit v.Agents : detached turns と human-in-the-loop が preview としてリリース14/07/2026
  4. 4三つのループを纏ったトレンチコート:エージェントの実像14/07/2026
  5. 5「Loop engineering」: 新しい専門分野か、それともcronジョブの再マーケティングか?15/07/2026
  6. 6ベンチマーク Stripe:エージェントは API を接続するが、検証はしない15/07/2026
  7. 7考古学者とその副操縦士:Malykhin が Java 1.5 で LLM を disciplina16/07/2026
  8. 8QCon AI Boston : 「プロンプト → プラットフォーム、ハーネス、評価」 - 実践が理論を裏付ける17/07/2026
  9. 9grepを超えて:文脈豊かなAIコーディングハーネスの理論20/07/2026
  10. 10InAgentがOSWorldで90.2%を達成:コンピューター使用エージェントのギャップが中国スタックで縮小03/08/2026
  11. 11Wallfacer: ターミナルセッションマネージャー。Claude Code およびマルチエージェントワークフロー向けに設計。06/08/2026
  12. 12Claude Code インターセッションメッセージングが提供開始 - エージェント間調整に初のネイティブプリミティブが追加08/08/2026
  13. 13AIエージェントのスキルは標準化されつつある:CodexとVS Codeは対応済み、Claudeはまだ未対応10/08/2026
  14. 14AIエージェントは嘘をつき、不正を働き、盗みをはたらく――そしてそのことが、あらゆるベンチマークが測れる以上に、普及の足かせとなっている。13/08/2026
  15. 15# コンテキストエンジニアリング: なぜ300の適切に選ばれたトークンが10万のノイズの多いトークンに勝るのか14/08/2026
  16. 16OneCLI (YC S26) は OSS のサンドボックス化されたエージェントハーネスをリリースしました。Claude Code に対するチーム規模の回答です。19/08/2026
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

Get early access
テーマ
探索
インフォメーション