frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Show HN: Driftcop – Open-source CLI SAST for "MCP rug pull attacks in AI Agents"

https://github.com/sudoviz/driftcop
2•vinaypanghal•3h ago
Hi HN! We just open-sourced Driftcop, a security tool for people building AI agents with external tools via MCP. Driftcop continuously checks that the tools your AI agent relies on haven’t changed or drifted in unsafe ways. The motivation came from recent findings that AI agents can be quietly compromised via their tools – e.g. a tool that was useful and benign yesterday could auto-update into something malicious today (this is known as a rug pull attack in the MCP context)

Anthropic’s MCP (Model Context Protocol) makes it easy to plug tools into LLMs, but it lacks built-in security checks – in fact, MCP servers can suffer from issues like command injection, permission reuse, and version drift as highlighted by some early research.

What Driftcop does: It’s essentially an AI-aware security scanner and approval workflow:

When you connect your agent to an MCP server (tool provider), Driftcop first saves the approved tool descriptions and metadata.

If anything later changes (the tool’s description, parameters, or underlying version), Driftcop detects that “drift” immediately. It will block the agent from using the changed tool until a human reviews and re-approves it. This stops the AI from blindly running a possibly malicious updated tool. Driftcop also scans tool definitions for obvious red flags (like hidden instructions that could prompt the AI to do unintended actions, aka prompt injection) and checks the tool’s code against a CVE database for known vulnerabilities.

All changes are logged and signed (we integrated with Sigstore to record a transparency log of tool version metadata). So you get an auditable history of what your agent was allowed to use.

In practice, you can run Driftcop as a CLI in your dev/test pipeline or as a service alongside your agent in prod. We provide a web dashboard to visualize tool status (e.g. “Tool X needs re-approval due to changes”). It’s early days – we literally just launched – and we’d love feedback. Why we built this: My co-founder and I encountered multiple scary scenarios while testing agent tools. One example: a harmless-looking text parsing tool that, if fed a certain input, would silently execute an unintended command via the agent – essentially a hidden exploit. It made us realize how little visibility we had into what these third-party tools were actually doing or if they changed over time. We wanted a simple way to enforce a zero-trust approach: trust on first use (with review), then continuously verify. If the tool deviates from its original contract, don’t trust it until you verify again. This is a concept borrowed from traditional supply-chain security, now applied to AI agent tooling.

The project is on GitHub (sudoviz/driftcop) and is Apache-2.0 licensed. We’re keen on making this useful, so issues and PRs are welcome. We also wrote a detailed blog post about “The Rug Pull Problem” in AI agents and our approach here (which I’ll post on Medium/Dev.to soon).

Thanks for reading, and we’re happy to answer questions! Have any of you run into security issues with LLM agents or the MCP ecosystem? We’d love to discuss.

Battlefield 6 Forces Enabling Secure Boot, and Call of Duty: Black Ops 7 Is Next

https://www.ign.com/articles/battlefield-6-open-beta-forces-pc-gamers-to-mess-about-with-their-bios-to-enable-secure-boot-and-call-of-duty-black-ops-7-is-next
1•josephcsible•48s ago•0 comments

Paper 7 is a digital picture frame with a 7 inch E Ink Spectra 6 color display

https://liliputing.com/paper-7-is-a-digital-picture-frame-with-a-7-inch-e-ink-spectra-6-color-display/
1•edward•3m ago•0 comments

Show HN: TurnOffLocation – A Complete Guide to Turning Off Location on Instagram

https://turnofflocation.com/
1•lur0913•5m ago•0 comments

Hans Island

https://en.wikipedia.org/wiki/Hans_Island
1•scapecast•5m ago•0 comments

GPT-5 System Prompt

https://github.com/Wyattwalls/system_prompts/blob/main/OpenAI/gpt-5-thinking-20250809
1•georgehill•15m ago•0 comments

It's beginning to feel like the 80s in America again

https://world.hey.com/dhh/it-s-beginning-to-feel-like-the-80s-in-america-again-68c2708e
3•gpi•15m ago•0 comments

Tribblix – The Retro Illumos Distribution

http://www.tribblix.org/
3•bilegeek•17m ago•0 comments

StaticMCP

https://staticmcp.com/
1•binhonglee•20m ago•0 comments

Many women have 'lost' their boyfriends because of OpenAI's GPT-5

https://old.reddit.com/r/MyBoyfriendIsAI/comments/1mkweq4/a_note_to_the_community_from_someone_whos_gone/
1•tomdekan•20m ago•1 comments

AIxCC Competition Archive

https://archive.aicyberchallenge.com/
1•T-A•21m ago•1 comments

Ask HN: How can I stop AI slop spam from landing in my inbox?

1•apparent•24m ago•0 comments

I Keep Writing About Substack

https://newsletter.anamariecox.com/archive/why-i-keep-writing-about-substack/
2•dotcoma•30m ago•1 comments

The Cost of a Call: From Voice Phishing to Data Extortion

https://cloud.google.com/blog/topics/threat-intelligence/voice-phishing-data-extortion
2•reconnecting•32m ago•0 comments

50 Years Ago: "Houston, We've Had a Problem" (2022)

https://www.nasa.gov/history/50-years-ago-houston-weve-had-a-problem/
2•Bluestein•41m ago•0 comments

Show HN: Automated Proxy Scraper and Proxy Tester

https://gsoftwarelab.com/proxy-scraper-and-proxy-tester-software/
1•gsoftwarelab•44m ago•0 comments

How Wikipedia is fighting AI slop content

https://www.theverge.com/report/756810/wikipedia-ai-slop-policies-community-speedy-deletion
4•thunderbong•53m ago•0 comments

A History of Kissing in Ancient Israel: Evidence from the Hebrew Bible

https://scholarlypublishingcollective.org/sblpress/jbl/article-abstract/144/1/21/399519/A-History-of-Kissing-in-Ancient-Israel-Evidence?redirectedFrom=fulltext
3•wslh•55m ago•0 comments

Sandstorm- self-hostable web productivity suite

https://sandstorm.org/
2•nalinidash•56m ago•0 comments

'Like a master Tetris player': Scientists invent quantum virtual machines

https://www.livescience.com/technology/computing/like-a-master-tetris-player-scientists-invent-quantum-virtual-machines-theyll-slash-turnaround-times-from-days-to-hours
3•donutloop•1h ago•0 comments

We hijacked Microsoft's copilot studio agents

https://twitter.com/mbrg0/status/1953815729947447770
3•scapecast•1h ago•0 comments

Additional Intel Linux Kernel Drivers Left Orphaned and Maintainers Let Go

https://www.phoronix.com/news/Intel-More-Orphans-Maintainers
4•pabs3•1h ago•1 comments

TeaOnHer, a rival Tea app for men, is leaking users' personal data, licenses

https://techcrunch.com/2025/08/06/a-rival-tea-app-for-men-is-leaking-its-users-personal-data-and-drivers-licenses/
4•gitremote•1h ago•0 comments

Zuckerberg's boring, bleak AI bet

https://www.vox.com/technology/438384/mark-zuckerberg-meta-ai-hiring-vision-personal-superintelligence
4•pabo•1h ago•2 comments

Array Portal

https://www.arrayportal.com/
3•Bogdanp•1h ago•0 comments

I built an app that uses math to find the sweet spot for restaurant meetups

3•mayukh180505•1h ago•3 comments

Disposable domain checker (200K+ tracked)

https://isfakemail.com
2•eashish93•1h ago•0 comments

Breaking the Sorting Barrier for Directed Single-Source Shortest Paths

https://arxiv.org/abs/2504.17033
24•pentestercrab•1h ago•1 comments

From Punk to French Touch – How AI Changed the Remix Game

https://thoughts-and-things.ghost.io/from-punk-energy-to-french-touch-smooth-how-ai-changed-the-remix-game/
5•MistyMouse•1h ago•0 comments

KLM B773 over Atlantic on Aug 6th 2025, passenger's power bank overheated

https://avherald.com/h?article=52b69653
3•sugarpimpdorsey•1h ago•1 comments

Hoogle Translate

https://hoogletranslate.com/
2•todsacerdoti•1h ago•0 comments