档案库 · 开发与企业工具 · 产品决策 · 2026
OneCLI押注智能体安全属于模型之外——秘密永不到达智能体
一个用于智能体秘密的Rust保险库变成了OneCLI(YC S26),一个开源团队管理工具——Show HN 161分在三月,Launch HN 88分在八月。
OneCLI
做的是什么生意
OneCLI is an open-source agent harness that gives each employee a sandboxed assistant connected to GitHub, Gmail, Notion, Dropbox or CRM from chat, under one org-wide policy: per-agent scoping, deterministic human approval for sensitive actions, an identity trail, and real credentials swapped in per request by a gateway the agent never touches.
启动资金:Y Combinator Summer 2026 standard package (reported ~$500,000 via SAFEs); no separate round disclosed.
起因
The founders had built ChartDB, an open-source database tool. When OpenClaw took off in January 2026 they started orchestrating agents on top of it and immediately hit an auth problem: agents needed credentials to do real work, but held them in memory and wrote them to local files, where a prompt injection could steal them. They built OneCLI in Rust as a vault for AI agents, launched it on Hacker News on 2026-03-12, and the Show HN drew 161 points and 52 comments.
经过
Demand came mostly from users of autonomous agents such as OpenClaw, Hermes and NanoClaw, and it exposed two missing pieces: managing secrets and permissions, and managing many agents for a team. So the founders pivoted from vault to harness — a sandboxed agent per employee, org-wide policy enforced at the network layer outside the model, placeholders instead of real secrets, human approval for risky calls, and a full identity trail. They joined YC's Summer 2026 batch, and the Launch HN on 2026-08-19 drew 88 points and 36 comments, mostly security engineers probing granularity, prompt-injection residue and a crowded market; the founders answered that they were still figuring out how to win it.
结果
As of September 2026 OneCLI is open source (Apache-2.0 with an enterprise folder), self-hostable in minutes, and listed as an active YC Summer 2026 company in San Francisco. HN commenters reported NanoClaw announcing OneCLI as its credential layer and 3,200+ GitHub stars within hours of launch; no revenue or customer names are public.
背景
OneCLI创始人是开源数据库工具ChartDB的创造者。当OpenClaw在2026年1月火爆时,他们开始在ChartDB之上编排智能体,并遇到了一个结构性问题:智能体需要凭据去执行,但持有真实密钥的智能体会将密钥保留在内存和本地文件中,提示注入或一个粗心的会话就可能泄露它们。他们用Rust构建的答案是一个网关——智能体获得占位符,真实凭据在网络层仅在策略检查后才被交换进去。
2026年3月12日的Show HN获得了161分和52条评论。来的用户大多在运行OpenClaw、Hermes和NanoClaw,他们下一步要求的不是更好的保险库,而是团队控制:每个员工的身份、组织范围的策略、敏感操作的批准。于是OneCLI从保险库扩展成管理工具——每位员工一个沙盒化智能体,通过聊天连接到GitHub、Gmail、Notion、Dropbox或CRM,在模型之外实施策略,并保留完整身份痕迹。
创始人拥有Axis Security的零信任网络和Argon的应用安全背景,加入了YC的2026年夏季批次,并于2026年8月19日在Hacker News上发布了管理工具,获得88分和36条评论。讨论既有采纳信号——NanoClaw将OneCLI作为其凭据层,发布后数小时内GitHub星标超过3200——也有安全工程师的尖锐问题,涉及策略细粒度、混淆代理风险和拥挤市场,创始人承认他们还没想好如何获胜。
这件事要成立,得有什么
- 给智能体一个原始API密钥在结构上不安全:秘密存在于模型上下文和本地文件中,提示注入能触及它——从模型中移除是唯一稳健的修复。
- 在模型之外实施类似零信任网络,创始人曾在Axis Security多年证明永不信任客户端,而在网络层面把关访问。
- 转变由用户驱动:运行OpenClaw和NanoClaw的保险库用户不断要求身份、策略和多人管理,单人工具无法满足。
- 开源是销售动作:公司必须信任智能体处理邮件、代码和CRM,需要阅读代码并自托管,而非相信厂商的安全承诺。
可借鉴之处
让用户指向真正的产品:保险库用户不断要求团队身份和策略,因此创始人把网关变成了更完整管理工具的一个功能,而不是停留在一个漂亮工具上。
后续进展
截至2026年9月5日,OneCLI是旧金山YC 2026年夏季的活跃初创公司,发布一个开源自托管的智能体管理工具。其八月发布公开信号:Launch HN帖88分、36条评论,有评论者称NanoClaw宣布OneCLI为其凭据层,发布数小时内GitHub星标超过3200,并在Y Combinator目录下有使用中的概要,合伙人是Brad Flora。公司不透露收入或客户名,创始人在HN帖中表示仍在思考如何赢得竞争激烈的智能体安全市场。
资料来源
- Show HN: OneCLI – Vault for AI Agents in Rust
- Launch HN: OneCLI (YC S26) – OSS sandboxed agent harness for teams
- OneCLI: The open source AI teammates for your company
发现哪里写错了?告诉我们。
轮到你了
你刚读完一家。说说你在做什么,看看谁在赌同一件事。
免费账号 · 3 次免费提问 · 不用绑卡