Skip to main content
Capital

Y Combinator Open-Sources QM, the AI Agent Harness It Uses to Run Itself

Y Combinator Open-Sources QM, the AI Agent Harness It Uses to Run Itself Image: Primary
Y Combinator announced Friday it has open-sourced QM, the internal agent harness the accelerator uses to manage fleets of AI agents across Slack and the web. The repository is live under the yc-software organization on GitHub and is licensed under MIT, allowing commercial use and modification without a waitlist. The GitHub README describes QM as a multiplayer agent harness designed for work environments. It provides each person and room with scoped memory, files, a keychain view, permissions, crons, web apps, and a durable sandbox. YC said it previously ran more than 50 Hermes agents for individual employees but found managing that fleet difficult, prompting the development of QM, short for quartermaster. The core runs on TypeScript with Node and Fastify, stores session history and memory in Postgres, and offers Slack as an optional in-process plugin. YC said it did not tie QM to a single model; the README notes that Pi, OpenCode, Codex, and Claude Code can all drive the same core. The project page states YC wanted a system it could own and host itself with control over credentials, logs, permissions, and the cloud account. The security section says QM follows the pattern of local coding agents where the agent acts using the person's credentials while actions are audited. It offers security postures ranging from strict human approval to a mode labeled dangerous with no pauses between tool calls. The code is available at github.com/yc-software/qm.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from startupfortune.com and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Capital
AI Capital

Profound raises $180 million at $1.8 billion valuation

AI marketing startup Profound has raised $180 million in a Series D round at a $1.8 billion valuation, according to a company announcement planned for Tuesday. Sequoia Capital and Kleiner Perkins co-led the financing. The supplied...

Security Infrastructure
Security Infrastructure

CISA flags ransomware use of VMware vCenter flaw

CISA updated its Known Exploited Vulnerabilities catalog to say ransomware gangs are actively abusing CVE-2026-59310, a critical VMware vCenter directory-traversal flaw patched by Broadcom in July, BleepingComputer reported. Broad...

Capital Products
Capital Products

Crane Venture Partners raises €419 million across four vehicles

Crane Venture Partners announced €419 million in committed capital across four investment vehicles and plans to build an inception-to-seed platform with MassMutual Ventures. The vehicles include Crane III at €146 million, a €129 m...

Security Infrastructure
Security Infrastructure

Sysdig details rapid Marimo exploit path to AWS-backed SSH access

Sysdig reported that a threat actor exploited CVE-2026-39987, a pre-authenticated remote-code-execution flaw in Marimo, then reached an SSH bastion host in eight seconds. The reported chain used credentials harvested from the comp...

Security
Security

Cisco patches exploited Secure Email Gateway flaw

Cisco warned customers to patch CVE-2026-76461, a critical Secure Email Gateway vulnerability it says is being actively exploited. Cisco said an unauthenticated remote attacker could send a crafted email containing malicious SQL s...

AI Products
AI Products

EUCLYD raises more than €200 million for AI compute systems

Eindhoven semiconductor-systems startup EUCLYD has raised a Series A round of more than €200 million, according to EU-Startups. Samsung, Somerset Capital Partners, the EQT-managed Scaleup Europe Fund and Innovation Industries co-...