We needed something like --dangerously-skip-permissions that doesn’t nuke your untracked files, exfiltrate your keys, or install malware.Claude Code's permission system is allow-or-deny per tool, but that doesn’t really scale. Deleting some files is fine sometimes. And git checkout is sometimes not fine. Even when you curate permissions, 200 IQ Opus can find a way around it. Maintaining a deny list is a fool's errand.nah is a PreToolUse hook that classifies every tool call by what it actually does, using a deterministic classifier that runs in milliseconds. It maps commands to action types like filesystem_read, package_run, db_write, git_history_rewrite, and applies policies: allow, context (depends on the target), ask, or block.Not everything can be classified, so you can optionally escalate ambiguous stuff to an LLM, but that’s not required. Anything unresolved you can approve, and configure the taxonomy so you don’t get asked again.It works out of the box with sane defaults, no config needed. But you can customize it fully if you want to.No dependencies, stdlib Python, MIT.pip install nah && nah installhttps://github.com/manuelschipper/nah
FL score
out of 100
Verdict
high confidence
Competition
6
competitors found, emerging market, funded players
Trend
No signal yet
A context-aware, deterministic permission guard for AI coding agents that addresses a critical and growing security vulnerability.
The pain
The gap
Build angle
Strengths
Questions about this idea?
FlyBot reads the scoring and gives you a second opinion on “A context-aware permission guard for Claude Code”.
Risks
Next steps
Fly Labs Method
Is the pain real, is there a gap, is it the right time, can one person build it.
High pain, clear gap with a narrow focus, strong payment signals, but the buildability for a truly comprehensive and 'out-of-the-box' solution by a solo builder is challenging.
Value Equation
Dream outcome and how likely it feels, against the time and effort it costs.
Strong market demand and value proposition in a growing market, but differentiation and implementation complexity are notable challenges.
One-Person Business
Curiosity pull, identity fit, and a path from free value to paid for a solo creator.
A clear, severe problem for a reachable audience with viable monetization, but the ongoing complexity of the 'deterministic classifier' makes it less simple for solo scaling.
Viral Frameworks
Hook strength, shareability, and how cheaply it can be tested.
Highly specific target audience and clear value proposition, with a viable business model, but dependent on the robustness of the deterministic classifier and competitive landscape.
Builder Lens
Evidence the problem exists, timing, defensibility, and a model that fits on a napkin.
Addresses a desperate and growing security problem for AI agents with a clear initial wedge, but needs more observed usage data.
Why this verdict
Five lenses, one composite. How scoring works
The angle
This weekend
Who is already there, emerging market
Permit.io provides fine-grained authorization for AI-powered applications, enforcing permissions across prompts, responses, actions, and data access, and integrates with emerging standards like MCP.
Pricing: Contact sales for pricing; offers a free tier for individual developers and small teams.
Corridor is purpose-built for securing AI-generated code, integrating directly with AI coding agents like Claude Code through hooks and MCP to provide real-time security feedback during code generation.
Pricing: Not publicly available, contact sales.
Snyk is an application security platform that includes SAST, SCA, and container security, and offers features to secure AI-generated code and integrate security into AI development practices.
Pricing: Free tier; Team plan from $25/month; Ignite plan for organizations with less than 50 developers at $1,260/year per contributing developer; Enterprise plan requires contacting sales.
Manifold is an AI Detection and Response (AIDR) platform designed to secure autonomous AI agents at runtime, defending endpoints from risks associated with rapid agent adoption.
Pricing: Not publicly available, contact sales.
Axiom aims to ensure AI-generated code is safe, secure, and accurate by using formal verification in Lean, providing mathematical certainty that code functions correctly and doesn't introduce vulnerabilities.
Pricing: Not publicly available, contact sales.
Knostic provides need-to-know access controls for large language models, preventing LLM-based enterprise applications from oversharing sensitive information through dynamic, context-aware data sharing.
Pricing: Not publicly available, contact sales.
What they charge
Recent news
Verifiable AI startup Axiom raises $200M to prove AI-generated code is safe to use
SiliconANGLE, March 12, 2026
Manifold Announces $8 Million Seed Funding Round to Secure Autonomous Endpoint AI Agents at Runtime
GlobeNewswire, March 18, 2026
Linux Foundation Announces $12.5M in Grant Funding to Advance Open Source Security
AIwire - HPCwire, March 20, 2026
Our latest investment in open source security for the AI era
Google Blog, March 17, 2026
Enhance AI security with Azure Prompt Shields and Azure AI Content Safety
Microsoft Azure Blog, June 05, 2025
Market signals
The market for securing AI-generated code and managing AI agent permissions is rapidly growing and receiving significant investment. The global AI code tools market is projected to reach $12.6 billion by 2028 and $70.55 billion by 2034, indicating a large and expanding market. Recent funding rounds, such as Axiom's $200M Series A and Manifold's $8M seed round, highlight investor confidence in solutions addressing AI security and trustworthy AI development.
What frustrates people
Last summer we faced a conundrum at my company, Tiger Data, a Postgres cloud vendor whose main business is in timeseries data. We were trying to grow our business towards emerging AI-centric workloads and wanted to provide a state-of-the-art hybrid search stack in Postgres. We'd already built pgvectorscale in house with the goal of scaling semantic search beyond pgvector's main memory limitations. We just needed a scalable ranked keyword search solution too.The problem: core Postgres doesn't provide this; the leading Postgres BM25 extension, ParadeDB, is guarded behind AGPL; developing our own extension appeared daunting. We'd need a small team of sharp engineers and 6-12 months, I figured. And we'd probably still fall short of the performance of a mature system like Parade/Tantivy.Or would we? I'd be experimenting long enough with AI-boosted development at that point to realize that with the latest tools (Claude Code + Opus) and an experienced hand (I've been working in database systems internals for 25 years now), the old time estimates pretty much go out the window.I told our CTO I thought I could solo the project in one quarter. This raised some eyebrows.It did take a little more time than that (two quarters), and we got some real help from the community (amazing!) after open-sourcing the pre-release. But I'm thrilled/exhausted today to share that pg_textsearch v1.0 is freely available via open source (Postgres license), on Tiger Data cloud, and hopefully soon, a hyperscalar near you:https://github.com/timescale/pg_textsearchIn the blog post accompanying the release, I overview the architecture and present benchmark results using MS-MARCO. To my surprise, we were not only able to meet Parade/Tantivy's query performance, but exceed it substantially, measuring a 4.7x advantage on query throughput at scale:https://www.tigerdata.com/blog/pg-textsearch-bm25-fu
AI
Hi HN!I recently switched from a Fedora/GNOME laptop to a MacBook Air. My old setup served me well as a portable workstation, but I’ve started traveling more while working remotely and needed something with similar performance but better battery life. The main thing I missed was a simple taskbar that shows the windows in the current workspace instead of a Dock that mixes everything together.I built boringBar so I would not have to use the Dock. It shows only the windows in the current Space, lets you switch Spaces by scrolling on the bar, and adds a desktop switcher so you can jump directly to any Space. You can also hide the system Dock, pin apps, preview windows with thumbnails, and launch apps from a searchable menu (I keep Spotlight disabled because for some reason it uses a lot of system resources on my machine).I’ve been dogfooding it for a few months now, and it finally felt polished enough to share.It’s for people who like macOS but want window management to feel a bit more like GNOME, Windows, or a traditional taskbar. It’s also for people like me who wanted an easier transition to macOS, especially now that Windows feels increasingly user-hostile.I’d love feedback on the UX, bugs, and whether this solves the same Dock/Spaces pain for anyone else.P.S. It might also appeal to people who feel nostalgic for the GNOME 2 desktop of yore. I started my Linux journey with it, and boringBar brings back some of that feeling for me.
AI
### Describe the project you are working on Godot C# bindings ### Describe the problem or limitation you are having in your project For the past weeks, I've been discussing with several Unity users intending to move to Godot C# regarding dealing with the C# garbage collector. The most common complaint I hear from users is that, in Unity, allocations can trigger unexpected GC spikes into the game. In Godot, we target to make all of the high performance APIs (those that intended to be called every frame) not allocate any memory, so theoretically the GC should not be a problem. Additionally, Godot starting from 4.0, uses the Microsoft CoreCLR version of .net, which also supposedly has a better garbage collector than Unity. But in all, after several discussions with Unity users, neither is enough reassurance for them, and they would really feel safer if Godot exposed a zero allocation API. ### Describe the feature / enhancement and how it helps to overcome the problem or limitation The idea of this proposal is that Godot exposes zero allocation versions of many functions in the C# API, that users can use if they desire. Technically, this could be done from the binding generator itself, without breaking compatibility, and without doing any modification to Godot itself. ### Describe how your proposal will work, with code, pseudo-code, mock-ups, and/or diagrams **WARNING** I am not familiar with C#, so take this as pseudocode. Imagine you have two functions exposed as to C#: ```C# void MyClass.SetArray( Vector2[] array); Vector2[] MyClass.GetArray(); ``` This works and is pretty and intuitive. However, it has two problems: * GC is allocated on return * Memory is copied to Godot native formats every time there is a call. The idea is to add NoAlloc versions, which can be generated directly by the binder automatically when required: ```C# void MyClass.SetArrayNoAlloc( Godot.Collections.PackedVector2Array array); void MyCl
AI