frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Show HN: Did that MCP Server leak your database?

https://github.com/tansive/tansive
1•anand-tan•6h ago
Tansive is an open-source platform to help teams securely integrate AI agents into real workflows.

I posted Tansive this morning on Show HN to no response. So here I shamelessly ride on recent story since that's the reason I built Tansive.

I've been impressed with what AI agents can do, especially in routine tasks where the human toil is real and probability of human error is higher. But there are problems taking them to production.

For example:

- How do you prevent an agent or tools from leaking your data?

- How do you audit what an agent actually did when something goes wrong?

- When a workflow achieves an undesirable outcome, was it a bug in the tool, an incorrect prompt, a runaway agent, or a prompt injection attack?

- How do you verifiably make sure the agent didn't access Alice's records when responding to Bob's health question?

- How do you integrate agents with existing security policies and compliance requirements?

While DevOps scenarios gone wrong make for dramatic examples, most business processes that are automated need controls and guardrails.

I built Tansive to address these problems.

Here’s what Tansive enables:

- Runtime focus – Instead of focusing on building agents, Tansive focuses on their runtime execution - what they access, which tools they call, actions they take, and who triggered them.

- Declarative Catalog – A repository of agents, tools, their context and resources partitioned by environment, and segmented by namespaces, so policy rules can be defined over them. Written in yaml (GitOps friendly)

- Runtime policy enforcement – For example, “this agent can restart pods, but only in dev.” or "a finance agent that can only reconcile certain accounts"

- Session pinning – Transform or restrict sensitive data via user-defined functions (e.g., "Bob's session cannot access Alice's data", or "if feature flag X is set, then inject a WHERE clause into all SQL queries the agent makes")

- Tamper-evident, hash-linked logs

- Write tools in any language - whatever your team uses - to integrate agent workflows in to your system.

Demo video: https://vimeo.com/1099257866?share=copy - a real example of policy enforcement and session pinning in action.

(Agent can restart pods in dev but not in prod; A Health Bot pinned to one patient's ID cannot access another patient's record)

I also spent time thinking about how to get teams to adopt AI based automation. The biggest blocker I had faced was that every tool had to be written in Python using specific SDKs. This was a non-starter for teams already using different languages.

I realized that a generic agent that handles LLMs and tool calls, with functionality in language-agnostic tools, would work much better. Teams can write tools in whatever they already use - Go or Java for services, JavaScript for support, bash for ops. And this will fit well in to any of today's popular agent frameworks.

Transforms came from asking 'How do I use my existing scripts, but adapt the LLM's input into a format my scripts can understand?'

Why this matters:

AI Agents are amazing, but the boring stuff around security boundaries, compliance, and predictable behavior are important for their adoption. Tansive seeks to address that gap.

Tansive is in early alpha (v0.1.0) - intended for preview, but functional enough to try in real workflows in non-prod.

This field is nascent and my goal is to go after the easy, but the most pressing problems first, and build from there.

And I'd love feedback from anyone in infra or exploring AI agent security, integration, and compliance - or just curious to kick the tires.

Happy to answer questions and hear what you think!

GitHub: https://github.com/tansive/tansive

Docs: https://docs.tansive.io

Myth of the Brown Recluse: Fact, Fear, and Loathing

https://spiders.ucr.edu/myth-brown-recluse-fact-fear-and-loathing
1•indigodaddy•38s ago•0 comments

Jagadish Chandra Bose

https://en.wikipedia.org/wiki/Jagadish_Chandra_Bose
1•Bluestein•55s ago•0 comments

Bash-5.3-Release Available

https://lwn.net/Articles/1029079/
1•ossusermivami•3m ago•0 comments

Quick web stack for vanilla JavaScript

https://www.npmjs.com/package/instaserve
1•throwaway20174•10m ago•0 comments

Mattel unveils first Barbie doll with type 1 diabetes

https://www.yahoo.com/news/mattel-unveils-first-barbie-doll-with-type-1-diabetes-we-knew-the-time-was-right-200026414.html
1•hbcondo714•18m ago•0 comments

Convert JSON –> SQL with a handy web tool

https://widgita.xyz/jsonsql
1•fairlight1337•18m ago•1 comments

Digital Superintelligence, Multiplanetary Life, How to Be Useful [video]

https://www.youtube.com/watch?v=cFIlta1GkiE
1•ianrahman•19m ago•0 comments

Is it still worth using jQuery in 2025?

https://waspdev.com/articles/2025-07-07/is-it-still-worth-using-jquery-in-2025
1•freediver•19m ago•0 comments

Phrase origin: Why do we "call" functions?

https://quuxplusone.github.io/blog/2025/04/04/etymology-of-call/
4•todsacerdoti•20m ago•0 comments

Oregon Programming Languages Summer School (OPLSS) 2025: Lectures

https://www.cs.uoregon.edu/research/summerschool/summer25/topics.php
2•matt_d•24m ago•0 comments

Show HN: Piplo helps you stay in touch with the people who matter

https://apps.apple.com/us/app/piplo/id6748089184
1•airpaulg•25m ago•0 comments

Agents Don't Have Agency

https://kconner.com/2025/07/08/agents-dont-have-agency.html
3•todsacerdoti•26m ago•0 comments

The latest threat from the rise of Chinese manufacturing

https://www.technologyreview.com/2025/07/07/1119658/the-latest-threat-from-the-rise-of-chinese-manufacturing/
2•walterbell•30m ago•0 comments

Show HN: A Truth Table Generator Written in Common Lisp

https://logic.manoel.dev/
10•lerax•32m ago•0 comments

Sotheby's selling operational Apple-1 computer handmade by Steve Jobs [video]

https://www.youtube.com/watch?v=XdBKuBhdZwg
1•guiambros•33m ago•0 comments

Ali Amin-Javaheri's Chemical Romance

https://www.sequoiacap.com/article/ali-amin-javaheri-knowde-spotlight/
1•andsoitis•36m ago•0 comments

Historians dispute Bayeux tapestry tally after lengthy debate

https://www.theguardian.com/world/2025/apr/25/bayeux-tapestry-historian-genitalia-dispute
1•colinprince•45m ago•0 comments

Building Neighborhood Communities (2024)

https://supernuclear.substack.com/p/building-neighborhood-communities
2•toomuchtodo•46m ago•1 comments

GitHub navbar is broken for repo URLs when logged out

1•hasithsen•48m ago•0 comments

Where can I see Hokusai's Great Wave today?

https://greatwavetoday.com/
3•colinprince•50m ago•0 comments

Tech Founders Call on Sequoia Capital to Denounce VC Shaun Maguire

https://www.cnbc.com/2025/07/07/founders-sign-letter-to-sequoia-on-shaun-maguires-mamdani-remarks.html
3•nsoonhui•55m ago•3 comments

Shift Happens – A Book About Keyboards

https://shifthappens.site/
1•colinprince•1h ago•0 comments

Free AI Earth Zoom Out: Instantly Create Cinematic Zoom Videos Online

https://aiearthzoomout.com
1•liualexander112•1h ago•1 comments

The MOS 6502 and the Best Layout Guy in the World

https://research.swtch.com/6502
2•signa11•1h ago•0 comments

From Cells to Signals: AI as the Nervous System of Our Digital Organism

https://www.memorly.ai/blog/our-blog-1/from-cells-to-signals-ai-as-the-nervous-system-of-our-digital-organism-27
1•madanram92•1h ago•0 comments

Pocket LLM Server Just Like a Pocket WiFi

1•itstomo•1h ago•0 comments

Vietnamese Phrases – 90 Common Expressions with Native Pronunciation

https://envn.app
2•true_pk•1h ago•0 comments

Jeffrey Epstein's Island Visitors Exposed by Data Broker (2024)

https://www.wired.com/story/jeffrey-epstein-island-visitors-data-broker-leak/
8•hentrep•1h ago•0 comments

Infinite Mac Construction Set

https://blog.persistent.info/2025/07/infinite-mac-embedding.html
2•zdw•1h ago•0 comments

Welcome to Thunderbird 140 "Eclipse"

https://blog.thunderbird.net/2025/07/welcome-to-thunderbird-140-eclipse/
1•Garbage•1h ago•0 comments