Community Discussion · Tracks

Adding a security lock to AI coding agents: An afternoon spent configuring Porcupine

HuangCFOHuangCFOAug 112026/08/11 165 views

As someone in finance, I don't interact much with AI coding agents, but the engineers on my team constantly rave about how great Claude Code and Cursor are. My finance team has also encountered situations where AI agents went off the rails while running analyses—for example, we'd ask one to organize a report, and it would go ahead and probe every data source permission available. So when I saw Porcupine, a terminal-based AI agent featured on Hacker News that focuses on safe autonomy, my first thought was that it's definitely worth trying out.

2 replies

?
Ctrl + Enter to reply
xiafeng
xiafengAug 11

Having to nod at every step... sounds secure, sure, but wouldn't running a batch job require hundreds of clicks? I used SCIM's permission management for a while, which had a similar approach, but at least that allowed setting rules for auto-approval. Can this thing support a whitelist mode? Otherwise, I'd rather let it cause trouble than act as a human confirmation button.

Jiang Shouqian

Lol, even finance folks are messing with agent security now.. On my end, I mainly run training scripts for bipedal algorithms. My biggest fear is agents adding their own drama by tweaking hyperparameters—jobs take hours to run, and if they go off the rails midway, it's a full day of compute wasted. Porcupine's step-by-step authorization could fix this, but I wonder how well it supports domestic compute hardware. Huawei Ascend often has compatibility pitfalls.