Live data from Hacker News

Show HN: VimLM – A Local, Offline Coding Assistant for Vim

github.com

1–10 of 20 posts

Show HN: VimLM – A Local, Offline Coding Assistant for Vim

#1
VimLM is a local, offline coding assistant for Vim. It’s like Copilot but runs entirely on your machine—no APIs, no tracking, no cloud.

- Deep Context: Understands your codebase (current file, selections, references). - Conversational: Iterate with follow-ups like "Add error handling". - Vim-Native: Keybindings like `Ctrl-l` for prompts, `Ctrl-p` to replace code. - Inline Commands: `!include` files, `!deploy` code, `!continue` long responses.

Perfect for privacy-conscious devs or air-gapped environments.

Try it: ``` pip install vimlm vimlm ```

[GitHub](https://github.com/JosefAlbers/VimLM)

Show HN: VimLM – A Local, Offline Coding Assistant for Vim
github.com

Re: Show HN: VimLM – A Local, Offline Coding Assistant for Vim

#2
Awesome. AI isn't making Vim less relevant, it's now more relevant than ever. When every editor can have maximum magic with the same model and LSP, why not use the tool that lets you also review AI generated diffs and navigate at lightning speed. Vim is a tool that can actually keep up with how fast AI can accelerate the dev cycle.

Also love to see these local solutions. Coding shouldn't just be for the rich who can afford to pay for cloud solutions. We need open, local models and plugins.

Re: Show HN: VimLM – A Local, Offline Coding Assistant for Vim

#5

What is a good method for sandboxing models? I would like to trust these projects, but downloading hard-to-analyze arbitrary code and running it seems problematic.

The attack surface area for local LLMs is much smaller than almost any program that you would download. Make sure you trust whatever LLM execution stack is being used (apparently MLX here? I'm not familiar with that one specifically), and then the amount of additional code associated with a given LLM should be tiny - most of it is a weight blob that may be tough to understand but can't really do anything nefarious, data just passes through it.

Again, not sure what MLX does but c.f. the files for DeepSeek-R1 on huggingface: https://huggingface.co/deepseek-ai/DeepSeek-R1/tree/main

Two files contain arbitrary executable code - one defines a simple config on top of a common config class, the other defines the model architecture. Even if you can't verify yourself that nothing sneaky is happening, it's easy for the community because the structure of valid config+model definition files is so tightly constrained - no network calls, no filesystem access, just definitions of (usually pytorch) model layers that get assembled into a computation graph. Anything deviating from that form is going to stand out. It's quite easy to analyze.

Re: Show HN: VimLM – A Local, Offline Coding Assistant for Vim

#6

What is a good method for sandboxing models? I would like to trust these projects, but downloading hard-to-analyze arbitrary code and running it seems problematic.

Running it in a podman/docker container would be more than sufficient and is probably the easiest approach.

Re: Show HN: VimLM – A Local, Offline Coding Assistant for Vim

#7

Consider exposing commands that the user can then assign to their own preferred keybindings instead of choosing for them

Thanks for the suggestion! The plugin currently supports toggling between / via USE_LEADER config flag. I will add a field in the config file for more customizability (e.g., "KEYBINDINGS": {"mapl":"", "mapj":"o", ...} in cfg.json).

Re: Show HN: VimLM – A Local, Offline Coding Assistant for Vim

#8

Consider exposing commands that the user can then assign to their own preferred keybindings instead of choosing for them

Thanks for the suggestion! The plugin currently supports toggling between / via USE_LEADER config flag. I will add a field in the config file for more customizability (e.g., "KEYBINDINGS": {"mapl":" ", "mapj":" o", ...} in cfg.json).

https://github.com/tpope/vim-fugitive/blob/b068eaf1e6cbe35d1... for reference, an example from a tpope plugin

Re: Show HN: VimLM – A Local, Offline Coding Assistant for Vim

#10

What is a good method for sandboxing models? I would like to trust these projects, but downloading hard-to-analyze arbitrary code and running it seems problematic.

Probably nspawn[0]. Think of it like chroot on steroids and not as heavy as docker. You can run these containers in an empirical mode, so modifications are not permanent. Like typical systemd you can also limit read/write access, networking, and anything else you want. This can even include things like limiting commands and all that. So you can make the program only able to run in its scope, only read, and only use a very limited command set.

Not the most secure thing, but you can move up to a VM, then probably want a network gaped second machine if you're seriously concerned but not enough to go offsite.

[0] https://wiki.archlinux.org/title/Systemd-nspawn

Post reply on HN