<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: M.S.</title>
    <description>The latest articles on DEV Community by M.S. (@michaels1011).</description>
    <link>https://dev.to/michaels1011</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4123605%2F8fb16394-0383-4eb9-b3b7-2eafa0e553bf.jpeg</url>
      <title>DEV Community: M.S.</title>
      <link>https://dev.to/michaels1011</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/michaels1011"/>
    <language>en</language>
    <item>
      <title>ephemora-cell 1.0.4: a stateless MCP tool server, now on PyPI!!</title>
      <dc:creator>M.S.</dc:creator>
      <pubDate>Mon, 21 Sep 2026 18:44:59 +0000</pubDate>
      <link>https://dev.to/michaels1011/ephemora-cell-104-a-stateless-mcp-tool-server-now-on-pypi-22dj</link>
      <guid>https://dev.to/michaels1011/ephemora-cell-104-a-stateless-mcp-tool-server-now-on-pypi-22dj</guid>
      <description>&lt;p&gt;No initialize handshake. No session state. Restart or load-balance the server between calls — clients never notice. tools/list answers with CacheableResult fields (ttlMs: 3600000, cacheScope: "private") so hosts can cache the tool list, and unknown versions are rejected with -32022 naming the supported list — never silently swallowed.&lt;/p&gt;

&lt;p&gt;Handshake-era clients (Claude Desktop, VS Code, Codex) keep working unchanged. Both eras, one process — with a test that runs them mixed against one server instance.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;get-policy now attests what execution actually grants
We caught our own policy report underreporting the filesystem surface: it said preopens: [] while every core-module run actually grants the ephemeral sandbox dir as /sandbox. The fix derives the reported preopens from the same truth as the run witness — and a test now executes a real tool and fails CI if report and witness ever diverge again:&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;python&lt;br&gt;
reported = engine.policy_for(spec)          # what get-policy says&lt;br&gt;
outcome  = engine.execute(spec, params)     # what actually ran&lt;br&gt;
assert reported["preopens"] == \&lt;br&gt;
       outcome.report.security_baseline["preopens"]&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;One version, three signals
The previous wheel said 1.0.3 on the box and 1.0.1 on the wire. Version is now single-sourced — and a test enforces pyproject.toml == runtime &lt;strong&gt;version&lt;/strong&gt; forever.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;How we verified it&lt;br&gt;
Fresh venv, plain pip install ephemora-cell, 13/13 acceptance checks against the published wheel: both MCP eras, version negotiation, policy/witness agreement, legacy compatibility unchanged. Bonus finding: the same echo call consumed identical fuel (21143) across two different installs on different machines — the determinism claim held in the wild.&lt;/p&gt;

&lt;p&gt;Try it&lt;/p&gt;

&lt;p&gt;bash&lt;br&gt;
pip install ephemora-cell&lt;br&gt;
ephemora-cell-mcp        # bundled clock + echo; --tools-dir for your own&lt;br&gt;
Feedback welcome — repo, issues and the full CHANGELOG are at &lt;a href="https://github.com/MichaelS1011/ephemora-cell" rel="noopener noreferrer"&gt;https://github.com/MichaelS1011/ephemora-cell&lt;/a&gt;&lt;/p&gt;

</description>
      <category>showdev</category>
      <category>webassembly</category>
      <category>mcp</category>
      <category>python</category>
    </item>
    <item>
      <title>1.000 concurrent sandboxes.

845 executions per second.
7.4 ms P50 latency.
0 errors.

Ephemora Cell on DGX Spark, isolation that actually scales.

Not just a sandbox. A measurable execution boundary.

https://github.com/MichaelS1011/ephemora-cell</title>
      <dc:creator>M.S.</dc:creator>
      <pubDate>Thu, 17 Sep 2026 10:50:57 +0000</pubDate>
      <link>https://dev.to/michaels1011/1000-concurrent-sandboxes-845-executions-per-second-74-ms-p50-latency-0-errors-4d7l</link>
      <guid>https://dev.to/michaels1011/1000-concurrent-sandboxes-845-executions-per-second-74-ms-p50-latency-0-errors-4d7l</guid>
      <description>&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
    &lt;div class="c-embed__content"&gt;
        &lt;div class="c-embed__cover"&gt;
          &lt;a href="https://github.com/MichaelS1011/ephemora-cell" class="c-link align-middle" rel="noopener noreferrer"&gt;
            &lt;img alt="" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Frepository-images.githubusercontent.com%2F1321694497%2F98612ab1-c052-4715-8347-cb34cf508506" height="640" class="m-0" width="1280"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="c-embed__body"&gt;
        &lt;h2 class="fs-xl lh-tight"&gt;
          &lt;a href="https://github.com/MichaelS1011/ephemora-cell" rel="noopener noreferrer" class="c-link"&gt;
            GitHub - MichaelS1011/ephemora-cell: Ephemora Cell — The execution layer for untrusted AI-generated code. Fast, capability-based WASM execution with explicit CPU, memory, time, I/O, and filesystem limits. · GitHub
          &lt;/a&gt;
        &lt;/h2&gt;
          &lt;p class="truncate-at-3"&gt;
            Ephemora Cell — The execution layer for untrusted AI-generated code. Fast, capability-based WASM execution with explicit CPU, memory, time, I/O, and filesystem limits. - MichaelS1011/ephemora-cell
          &lt;/p&gt;
        &lt;div class="color-secondary fs-s flex items-center"&gt;
            &lt;img alt="favicon" class="c-embed__favicon m-0 mr-2 radius-0" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fgithub.githubassets.com%2Ffavicons%2Ffavicon.svg" width="32" height="32"&gt;
          github.com
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;


</description>
      <category>security</category>
      <category>opensource</category>
      <category>showdev</category>
      <category>startup</category>
    </item>
    <item>
      <title>Ephemora Cell: a capability-based WASM sandbox for untrusted AI code</title>
      <dc:creator>M.S.</dc:creator>
      <pubDate>Sun, 13 Sep 2026 22:00:00 +0000</pubDate>
      <link>https://dev.to/michaels1011/ephemora-cell-a-capability-based-wasm-sandbox-for-untrusted-ai-code-3eii</link>
      <guid>https://dev.to/michaels1011/ephemora-cell-a-capability-based-wasm-sandbox-for-untrusted-ai-code-3eii</guid>
      <description>&lt;p&gt;AI agents do not only answer questions. They write code, call tools, and load plugins. The hard part is not starting that work. It is what the code is allowed to do once it runs.&lt;br&gt;
Permission systems answer “may it run?”&lt;/p&gt;

&lt;p&gt;They do not answer “how far may it run?”&lt;br&gt;
Ephemora Cell is a small open-source execution layer for that second question. It runs untrusted workloads inside a capability-limited WASI runtime: agents, MCP tools, plugins, code interpreters.&lt;br&gt;
Repo: &lt;a href="https://github.com/MichaelS1011/ephemora-cell" rel="noopener noreferrer"&gt;https://github.com/MichaelS1011/ephemora-cell&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;pip install ephemora-cell · Apache-2.0&lt;/p&gt;

&lt;p&gt;The shape of the problem&lt;br&gt;
AI Agent → Tool / MCP → Ephemora Cell → WASM → bounded result&lt;/p&gt;

&lt;p&gt;Cell is not an agent framework. It sits under the stack you already have. The guest gets only the capabilities you grant. Everything else is closed by default.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Same attacks, different boundary&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;We ran eight documented attack primitives against:&lt;/p&gt;

&lt;p&gt;a stock python:3.12-slim container&lt;br&gt;
Ephemora Cell&lt;/p&gt;

&lt;p&gt;In that comparison: Docker 0/8 blocked, Cell 8/8 blocked.&lt;/p&gt;

&lt;p&gt;Shell, fork, sockets, host filesystem, symlink-style escapes, and related vectors are covered by the suite in the repo. Reproduce with the scripts under assets/ and benchmarks/.&lt;br&gt;
This is not a universal security guarantee. It is a measured comparison for those vectors. Cell does not decide whether guest code is “good.” A module can still misbehave inside the budgets it received.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Performance&lt;/strong&gt; (why you can sandbox every call)&lt;br&gt;
Cold-starting a container for every tool call is expensive. Cell is aimed at warm, per-call isolation. On our published benchmarks, pooled warm runs sit in the sub-millisecond range for a simple guest; raw results live under benchmarks/results/. Always treat latency numbers as workload- and machine-specific.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;MCP&lt;/strong&gt;: tools need a runtime&lt;br&gt;
An MCP tool is not only a JSON schema. It is code that runs.&lt;br&gt;
Cell ships a dependency-free MCP stdio server. Tools are WASM modules executed inside the same boundary. Responses can carry execution metadata: cost (fuel, ms), policy, and outcome — so “what did it return?” and “under which limits?” stay together.&lt;/p&gt;

&lt;p&gt;pip install ephemora-cell&lt;br&gt;
ephemora-cell-mcp&lt;/p&gt;

&lt;p&gt;There is also a GitHub Action to run WASM in CI under the same class of limits (including an isolated path with OS-level walls).&lt;/p&gt;

&lt;p&gt;Any language that compiles to WASI/WASM can be a guest. The repo CI exercises several toolchains.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What Cell is — and is not&lt;/strong&gt;&lt;br&gt;
Is: an execution primitive with explicit, enforceable limits and inspectable results.&lt;/p&gt;

&lt;p&gt;Is not: a claim that models are safe, that prompt injection is solved, or that residual risk is zero.&lt;/p&gt;

&lt;p&gt;Trust comes from a narrow boundary and budgets you can measure — not from a promise that the guest is benign.&lt;/p&gt;

&lt;p&gt;If you build agents or MCP tools and care about what happens after the tool is selected, take a look at the repo, run the attack scripts, and break it. Technical criticism is welcome, especially on the WASI surface and the vector suite.&lt;/p&gt;

&lt;p&gt;GitHub: &lt;a href="https://github.com/MichaelS1011/ephemora-cell" rel="noopener noreferrer"&gt;https://github.com/MichaelS1011/ephemora-cell&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>mcp</category>
      <category>ai</category>
      <category>opensource</category>
    </item>
  </channel>
</rss>
