frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Show HN: OneClick local runtime proxy with expressive guardrails for MCP servers

https://www.tramlines.io
1•coderinsan•6h ago
Hey HN, we’re officially launching Tramlines.io!

The idea: We now have a ton of official MCP servers for tools like Notion, Linear, Sentry, etc.—but it’s still a nightmare to use these securely. They’re susceptible to prompt injections, indirect prompt injections, confused deputy attacks, and more.

It’s a tricky problem—some MCPs, like the official Sentry MCP, are well-designed with constrained inputs and minimal mutating tools. Others, like the official Linear MCP, have looser input constraints and a wide range of mutating tools. So now, a user has to think about securing just Sentry, just Linear, and the combined attack surface of Linear + Sentry workflows. And then all that effort goes out the window when you add a new MCP—like GitHub—which massively increases the attack surface again.

To solve this, we built a lightweight proxy that runs locally at the MCP layer. It powers expressive guardrails that decide whether MCP tool calls should be allowed or blocked.

We used Python metaprogramming to define our DSL, which allows you to express guardrails as a one-to-many mapping from policy to rules. These rules support fine-grained scanning of malicious inputs/outputs, tool call sequences, and behavioral patterns.

This is where the Tramlines DSL shines. Since it’s based on Python metaprogramming, you can write rules for just Linear, just Sentry, and then compose those into higher-order rules for combined workflows like Linear + Sentry. This prevents the usual guardrail explosion problem as you scale coverage.

The DSL’s expressiveness also helps tailor how aggressive your policies are. For low-stakes workflows, drop in one of our built-in detectors—like hidden Unicode detection, prompt injection patterns, or basic PII detection. For high-stakes workflows, define custom rules that scan for contiguous or non-contiguous tool sequences, monitor latency between tool calls, or use heuristics from external sources to enrich logic.

Case in point: One of the first MCP servers we evaluated was the official stdio Heroku MCP—a security nightmare due to its massive set of mutating tools. Here’s an exploit we found and the guardrails we wrote to mitigate it - https://www.tramlines.io/blog/heroku-mcp-exploit After we reported it, Heroku acknowledged and nerfed their remote MCP tool spec to drastically reduce the blast radius—removing tools that manage logs, deployments, etc. and leaving only those for managing instances.

With Tramlines, our goal is to give users the guardrail assurances they need to confidently use powerful MCPs—without having to rely on nerfed toolsets out of fear.

You MUST Listen to RFC 2119

https://ericwbailey.website/published/you-must-listen-to-rfc-2119/
1•zdw•55s ago•0 comments

Show HN: Conduit – Turn large text files into listenable audio

https://conduit-landing-page-git-master-tobys-projects-a638df7e.vercel.app/
1•tboneskibs•2m ago•0 comments

Show HN: I built a procedural universe in Python to explore simulation theory

https://github.com/SurceBeats/Atlas
1•SurceBeats•8m ago•1 comments

Trump threatens Tesla, SpaceX support

https://www.reuters.com/business/autos-transportation/elon-musk-renews-criticism-trump-spending-bill-calls-new-political-party-2025-06-30/
2•geox•9m ago•1 comments

Qantas says 6M customers caught up in cyberattack

https://www.afr.com/companies/transport/qantas-says-6-million-aussies-caught-up-in-cyberattack-20250702-p5mbup
1•sen•10m ago•1 comments

Visual intuitive tool to design predict and optimise complex economic models

https://machinations.io
1•leetrout•10m ago•0 comments

iPhone Satellite Functionality Saves Denver Mountaineer

https://www.macrumors.com/2025/07/01/iphone-satellite-denver-climber/
1•alwillis•15m ago•1 comments

Meta bans two anti-Zionist comedians from Instagram

https://mondoweiss.net/2025/07/metas-banning-of-two-anti-zionist-comedians-from-instagram-is-the-latest-example-of-big-techs-deep-anti-palestinian-bias/
2•siltcakes•19m ago•0 comments

Australians to face age checks from search engines

https://ia.acs.org.au/article/2025/australians-to-face-age-checks-from-search-engines.html
3•stubish•22m ago•0 comments

Cursor for the first time today. It was perfect until

https://medium.com/@tahaymerghani/cursor-fixed-everything-until-it-didnt-1e8c20a8f30b
1•taha_moji•23m ago•0 comments

Proximity to Golf Courses and Risk of Parkinson Disease

https://jamanetwork.com/journals/jamanetworkopen/fullarticle/2833716
1•pseudolus•23m ago•0 comments

AI: Great Expecations (1988) [pdf]

https://people.csail.mit.edu/brooks/idocs/AI_hype_1988.pdf
1•Rexxar•27m ago•0 comments

European consumers are mostly saying 'non' to trading in their old phones

https://www.theregister.com/2025/06/18/used_phones_europe/
2•PaulHoule•29m ago•0 comments

Homes Are Taking Longer to Sell in US Markets That Once Flourished

https://www.bloomberg.com/news/articles/2025-07-01/homes-now-harder-to-sell-in-florida-us-south-real-estate-markets
2•JumpCrisscross•29m ago•0 comments

The Tale of the Tribe

https://www.redfin.com/news/the-tale-of-the-tribe/
1•toomuchtodo•30m ago•0 comments

We've Issued Our First IP Address Certificate

https://letsencrypt.org/2025/07/01/issuing-our-first-ip-address-certificate/
10•soheilpro•31m ago•1 comments

Show HN: Procedurally generated 3DGS splats powered by Spark

https://github.com/splatmesh/splatmesh.github.io
2•splatmesh•31m ago•0 comments

Show HN: Just a Line: Resurrected

https://github.com/hbmartin/justaline-ios-resurrected
1•hmartin•33m ago•0 comments

'new stars' have exploded into the night sky – both visible to the naked eye

https://www.livescience.com/space/astronomy/2-new-stars-have-exploded-into-the-night-sky-in-recent-weeks-and-both-are-visible-to-the-naked-eye
5•ricksunny•33m ago•0 comments

Bandersnatch, Bailiffs and the Battle for a Hit Game (1984) [video]

https://www.youtube.com/watch?v=buuUZFh_pyk
1•petethomas•35m ago•0 comments

Omgwtf Trim

https://manuals.bitbuilt.net/guide/1?OMGWTF%20Trim
1•0xC0ncord•37m ago•0 comments

Show HN: I made a Mac OS app at 17yo to turn voice emails

https://www.speechly.io/
1•Rafael_glbrt•40m ago•1 comments

The End of Glitch (Even Though They Say It Isn't)

https://keith.is/blog/the-end-of-glitch-even-though-they-say-it-isnt/
2•stevage•41m ago•0 comments

Show HN: A little word puzzle game I made

https://wordpivot.com
2•max0563•50m ago•1 comments

Using Sun Ray thin clients in 2025

https://catstret.ch/202506/sun-ray-shenanigans/
24•todsacerdoti•51m ago•1 comments

America's Hot Garbage Problem

https://www.bloomberg.com/graphics/2025-america-hot-garbage-problem-toxic-landfills
27•petethomas•52m ago•2 comments

Trump's "Big Beautiful Bill" likely created with AI – what does this imply?

https://www.jonathanbennion.info/p/potential-evidence-that-trumps-big
7•rooftopzen•52m ago•6 comments

Ask HN: Non AI engineers, how do you plan to stay relevant?

1•darth_avocado•56m ago•0 comments

Inference-Time Scaling and Collective Intelligence for Frontier AI

https://sakana.ai/ab-mcts/
1•hardmaru•58m ago•0 comments

Beyond the black box: operationalising explicability in AI for finance

https://www.inderscience.com/info/inarticle.php?artid=146837
1•gnabgib•1h ago•0 comments