Ve

Vectimus – Cedar policy enforcement for AI coding agents

Hacker News

Vectimus – Cedar policy enforcement for AI coding agents

Hey HN. I built Vectimus because coding agents keep doing things they shouldn't and there's no runtime governance layer for the developer workstation. The problem: Claude Code, Cursor, Gemini CLI and GitHub Copilot let agents execute shell commands, write files and call MCP servers. Most developers disable the permission prompts because they slow you down. But that means the agent can rm -rf /, read your .env, push to production or call a compromised MCP server with nothing watching. Vectimus intercepts every tool call and evaluates it against 78 Cedar policies containing 369 rules before execution. Cedar is the policy language AWS chose for AgentCore Policy (GA this month). Evaluation runs locally via a persistent daemon in under 10ms. Zero network calls. Zero telemetry. Every evaluation produces an Ed25519-signed receipt so you have cryptographic proof of what was allowed and denied. Every policy maps to a real incident. CVE-2025-6514 compromised 437,000+ developer environments through a malicious MCP OAuth proxy. The GitHub MCP server was hijacked via a crafted issue to exfiltrate private repo data. A Terraform agent destroyed production infrastructure. These happened. How it hooks in: Claude Code intercepts shell commands, file writes, MCP calls and web fetches. Cursor governs shell commands, file reads/writes and MCP tool calls at the editor level. Copilot intercepts terminal commands, file edits, deletes and git pushes. Gemini CLI uses Gemini's native hook system. MCP servers are blocked by default and allowlisted per-project with input inspection. Observe mode lets you see what would be blocked before you enforce. I also built Sentinel ( https://github.com/vectimus/sentinel ), a three-agent pipeline that scans for new agentic AI security incidents daily, drafts Cedar policies, replays the incident in a sandbox to prove the policy catches it, then opens a PR. The pipeline is governed by Vectimus. Every finding and policy draft is public. All 10 OWASP Agentic Top 10 categories covered. Compliance annotations for SOC 2, NIST AI RMF, NIST CSF 2.0, EU AI Act, ISO 27001, CIS Controls and SLSA. Apache 2.0. Solo founder, built in Ireland. Happy to go deep on the Cedar policy design, the hook architecture, the signed receipts or the OWASP mapping.

Share card

Actual performance

3points
2comments
Did not reach leaderboard

Launch Intel predictions

Analyze your own launch →
Product HuntOn track for Day 1 leaderboard · Strong signals: agents, agent, cursor · Missing: mac, macos, model
99%99% predicted probability of success on Product Hunt, based on ML models trained on real launch data.
best fitHighest predicted score across all platforms for this description.
Indie HackersFits the IH revenue-focused audience · Strong signals: gemini · Missing: supports, reddit linkedin, podcasting
50%50% predicted probability of success on Indie Hackers, based on ML models trained on real launch data.
Hacker NewsMay not resonate with HN audience · Strong signals: lua, ide, pipe · Missing: https docs, excited, just released
38%38% predicted probability of success on Hacker News, based on ML models trained on real launch data.
nativeThis product was originally launched on this platform.
TrustMRRLess likely to generate early MRR · Strong signals: month · Missing: mobile apps, ios, personal
36%36% predicted probability of success on TrustMRR, based on ML models trained on real launch data.
Acquire.comPre-revenue stage for this audience · Missing: arr, mrr, revenue
25%25% predicted probability of success on Acquire.com, based on ML models trained on real launch data.
AppSumoMay struggle as an AppSumo deal · Strong signals: calls · Missing: plus, platform, intuitive
21%21% predicted probability of success on AppSumo, based on ML models trained on real launch data.
BetaListMay not resonate with beta-testers · Strong signals: crypto · Missing: web3, chat, cryptocurrency
0%0% predicted probability of success on BetaList, based on ML models trained on real launch data.

Correct prediction on native model

Similar products

Axel
Axel91%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Todoist for AI coding agents

Product Hunt+269Task Management
Baton
Baton91%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Orchestrate your AI coding agents

Product Hunt+106Developer Tools
BriefGate
BriefGate31%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Client intake for AI coding agents

Indie Hackerscommitment-side-project
DznDna
DznDna34%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

The design library for AI coding agents

TrustMRRDesign Tools
PMB
PMB88%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Stop re-explaining your project to AI coding agents

Product Hunt+207Open Source
Sy
Symphony – a live map of your AI coding agents26%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Symphony – a live map of your AI coding agents

Hacker News3
agmsg
agmsg83%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Stop copy-pasting between your AI coding agents

Product Hunt+239Open Source
HolyCode Cloud
HolyCode Cloud48%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Always-on cloud workstation for AI coding agents

Indie Hackerscommitment-full-time
Straion
Straion85%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Manage Rules for AI Coding Agents

Product Hunt+380Developer Tools
Joxo
Joxo15%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

The team channel for AI coding agents

Indie Hackerscommitment-full-time