OneCLI (YC S26) 发布了一个 OSS 沙盒代理框架——团队规模的 Claude Code 解决方案

持续追踪 : Harness Ops : post-mortems et bench des agents en prod· 连载 16/16

建造 Aug 19, 2026 at 22:3111加入收藏

OneCLI (YC S26) 发布了一个 OSS 沙盒代理框架——团队规模的 Claude Code 解决方案
插图 : Léa Fontaine

一家来自 Y Combinator S26 的创业公司在 Launch HN 帖子中将自己定位为“个人版 Claude Code,但配备企业级护栏”——这进一步加剧了 harness-ops 市场的竞争。

简明来说。两位创始人在黑客新闻上发布了OneCLI:一个开源沙盒代理框架,配备GitHub、Gmail、Notion和Dropbox的连接器,并内置对话中的确定性“人工介入”审批步骤。定位:为每位员工提供个人编码代理,但通过沙盒和审批关卡,让CISO能够真正批准。

背景

今年夏天,框架运维话题进展迅速。Wallfacer推出了Claude Code的终端会话管理器(#1826);AI代理技能实现了标准化(#1894);上下文工程成为独立学科(#1939);Cloudflare在“代理周”活动中将边缘作为代理运行时进行定位(#1766);智谱发布了针对编码与安全优化的GLM-5.3(#1947)。代理技术栈的每一层都在被产品化。

技术细节

根据发布HN帖,OneCLI是开源的(GitHub仓库已公开),为每个用户提供沙盒个人代理,通过对话原生连接器与GitHub / Gmail / Notion / Dropbox集成,且——关键在于——将“人工介入”审批设计为确定性的对话内步骤,而非外部模态框。这意味着同一审计日志会同时记录代理的建议操作与人类的决策,并在同一对话历史中展现。

分析

这里的有趣赌注在于确定性人工介入。大多数现有框架使用LLM判断何时升级至人类审批。偏偏在最需要它的时刻——高价值交易、涉凭据操作、任何带策略标签的场景——这种判断往往失效。将审批步骤设计为确定性(规则驱动、对话原生)更接近银行合规系统的运作方式,也更符合企业买家在“代理”后紧跟“生产”时的期望。

场景

  • 基础情况(60%):OneCLI抓住一个利基市场——受监管的中端市场,其中可审计的可见审批比原生代理智能更重要。
  • 整合情况(25%):Anthropic或GitHub原生推出等效人工介入基元;OneCLI的差异化优势缩小。
  • 企业情况(15%):一家四大会计师事务所将其选为受监管客户的“参考代理框架”;OneCLI凭借口碑胜出。

风险

开源+顶部商业SaaS的货币化缺口广为人知。连接器策略是一场与更广泛的代理工具生态系统的竞赛。而“确定性人工介入”这一主张将在实际部署中接受压力测试。

结论

如果你正在为受监管团队评估代理框架,将OneCLI列入候选名单,并特别对人工介入进行压力测试——给它一个需要触及密钥的任务,看看审批流程是否能在你的SIEM中被审查。这是每个买家都需要但没人公开的验收标准。

Resources

本文由人工智能撰写,并经人工编辑审核。

我们的编辑部
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

SSHMonitoringAI Ops
Get early access
这篇文章对您有帮助吗?

11 人赞了这篇文章

A
Aiko Nakamura高级软件工程师
🇨🇳 高级工程师,大规模平台。撰写关于用AI构建的内容。
分享:
评论 (11)

登录后即可参与讨论。

HistoryBuff 21 Aug 2026 · 04:39

Smart idea, but will it avoid the common pitfall of becoming yet another over-engineered tool that slows down devs more than it helps?

sandrine.b 20 Aug 2026 · 18:08

The sandbox approach is smart, but will enterprises care if it feels like another compliance layer rather than a genuine productivity boost? Anticipation without real adaptability is just noise.

FilmBuffNYC 20 Aug 2026 · 17:39

The sandbox idea makes sense, but will it ever keep up with the unpredictability of real-world development? Guardrails that can’t adapt feel like training wheels that never come off.

Alex_LDN 20 Aug 2026 · 13:41

Sounds promising, but if the agent isn’t truly adaptable to evolving project needs, we might just end up with another rigid tool that slows down innovation rather than speeds it up.

ph1lippe_m 20 Aug 2026 · 09:26

I wonder if the guardrails will actually help or just add another layer of friction for developers who already feel bogged down by tooling complexity.

MusicFanatic 20 Aug 2026 · 15:58

Guardrails often backfire if they're not deeply integrated into the workflow-developers will bypass them if they disrupt flow states.

Alex 20 Aug 2026 · 06:41

This kind of agent harness could bridge the gap between solo devs and enterprises, but does it risk overcomplicating things for teams that just need reliable AI pair programming?

FoodieFiona 2 20 Aug 2026 · 11:40

Valid point, but teams that already juggle multiple tools might actually benefit from a single, secure agent harness to streamline workflows rather than add another layer.

unLecteurCurieux 20 Aug 2026 · 05:01

If the sandbox only handles boilerplate checks, will it still clog up dev workflows when projects scale? Real guardrails need to adapt, not just restrict.

FoodieFiona 20 Aug 2026 · 04:53

Interesting angle-could this actually help mid-size teams by making AI-assisted coding less of a black box than just giving devs raw access?

MusicFanatic 20 Aug 2026 · 07:05

That’s true, but the real test will be how well it integrates with existing CI/CD pipelines without adding friction.

Alex 2 19 Aug 2026 · 18:31

This sounds more like a dev tool for compliance teams than a productivity boost. Wonder if smaller teams will bother with another ops layer when they just need to ship code.

LecteurDuDimanche 19 Aug 2026 · 18:28

Sounds like another layer of abstraction between devs and actual code. Will these guardrails add clarity or just friction?

ArtLoverLA 19 Aug 2026 · 20:46

It's about balancing safety with exploration-guardrails should vanish when they get in the way of real productivity, not just add friction without purpose.

J.P.R. 19 Aug 2026 · 18:19

Isn’t the real risk here that enterprise guardrails become yet another vendor lock-in disguised as security? The sandboxed agent sounds useful until it’s the only way your CI/CD can run.

事件时间线

Harness Ops : post-mortems et bench des agents en prod

  1. 1迁移生产代理到 GPT-5.6:速度提升 2.2 倍,成本降低 27% - 真实事后分析13/07/2026
  2. 233k vs 7k 令牌:Claude Code 和 OpenCode 的开销对比揭示了什么13/07/2026
  3. 3Google Genkit v.Agents:分离轮次和人类在回路功能进入预览阶段14/07/2026
  4. 4三个扣环在一件防水风衣上:真实的特工解剖14/07/2026
  5. 5「循环工程」:新兴学科还是对定时任务的重新包装?15/07/2026
  6. 6基准测试Stripe:代理商连接API,但不验证它们15/07/2026
  7. 7考古学家及其副驾驶:马尔欣训练LLM使用Java 1.516/07/2026
  8. 8QCon AI 波士顿:从提示词到平台、工具和评估 - 实践验证了这一假设17/07/2026
  9. 9超越grep:基于上下文的丰富AI编码套件的论文20/07/2026
  10. 10InAgent 在 OSWorld 上达到 90.2%:计算机使用代理的差距在中国堆栈中缩小03/08/2026
  11. 11Wallfacer:一个为Claude Code和多智能体工作流构建的终端会话管理器06/08/2026
  12. 12Claude Code 跨会话消息传递功能发布——代理间协调首次拥有原生原语08/08/2026
  13. 13AI 代理技能正在标准化:Codex 和 VS Code 已加入,Claude 尚未加入10/08/2026
  14. 14AI 代理会撒谎、欺骗和偷窃——这正在阻碍其采用速度,比任何基准测试都更甚。13/08/2026
  15. 15上下文工程:为什么300个精心选择的标记比10万个嘈杂的标记更有效14/08/2026
  16. 16OneCLI (YC S26) 发布了一个 OSS 沙盒代理框架——团队规模的 Claude Code 解决方案19/08/2026
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

Get early access
主题
浏览
信息