
Extensible Software in the Age of LLMs: How to Ship a Core Users Can Extend Safely
Making software extensible software in the age of LLMs is a product-boundary decision before it is a runtime decision. Keep a small, accountable core; put the long tail of one-user requests on an extension point; and give untrusted extension code a narrow capability instead of a credential. The sandbox you choose matters less than the boundary you draw. That is the short version of the argument Jeremy Morrell published on 2026-08-18 in “Extensible software in the age of LLMs”, which reached the Hacker News front page at 177 points and 88 comments the next day (HN item 49363668). This guide turns that essay into a decision process: when to expose an extension point, what to hand it, which isolation primitive fits, and when the answer is that you should not build one at all. ...
