frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

ClawEmail: 1min setup for OpenClaw agents with Gmail, Docs

https://clawemail.com
1•aleks5678•3m ago•1 comments

UnAutomating the Economy: More Labor but at What Cost?

https://www.greshm.org/blog/unautomating-the-economy/
1•Suncho•10m ago•1 comments

Show HN: Gettorr – Stream magnet links in the browser via WebRTC (no install)

https://gettorr.com/
1•BenaouidateMed•11m ago•0 comments

Statin drugs safer than previously thought

https://www.semafor.com/article/02/06/2026/statin-drugs-safer-than-previously-thought
1•stareatgoats•13m ago•0 comments

Handy when you just want to distract yourself for a moment

https://d6.h5go.life/
1•TrendSpotterPro•14m ago•0 comments

More States Are Taking Aim at a Controversial Early Reading Method

https://www.edweek.org/teaching-learning/more-states-are-taking-aim-at-a-controversial-early-read...
1•lelanthran•16m ago•0 comments

AI will not save developer productivity

https://www.infoworld.com/article/4125409/ai-will-not-save-developer-productivity.html
1•indentit•21m ago•0 comments

How I do and don't use agents

https://twitter.com/jessfraz/status/2019975917863661760
1•tosh•27m ago•0 comments

BTDUex Safe? The Back End Withdrawal Anomalies

1•aoijfoqfw•29m ago•0 comments

Show HN: Compile-Time Vibe Coding

https://github.com/Michael-JB/vibecode
5•michaelchicory•32m ago•1 comments

Show HN: Ensemble – macOS App to Manage Claude Code Skills, MCPs, and Claude.md

https://github.com/O0000-code/Ensemble
1•IO0oI•35m ago•1 comments

PR to support XMPP channels in OpenClaw

https://github.com/openclaw/openclaw/pull/9741
1•mickael•36m ago•0 comments

Twenty: A Modern Alternative to Salesforce

https://github.com/twentyhq/twenty
1•tosh•37m ago•0 comments

Raspberry Pi: More memory-driven price rises

https://www.raspberrypi.com/news/more-memory-driven-price-rises/
1•calcifer•43m ago•0 comments

Level Up Your Gaming

https://d4.h5go.life/
1•LinkLens•47m ago•1 comments

Di.day is a movement to encourage people to ditch Big Tech

https://itsfoss.com/news/di-day-celebration/
3•MilnerRoute•48m ago•0 comments

Show HN: AI generated personal affirmations playing when your phone is locked

https://MyAffirmations.Guru
4•alaserm•49m ago•3 comments

Show HN: GTM MCP Server- Let AI Manage Your Google Tag Manager Containers

https://github.com/paolobietolini/gtm-mcp-server
1•paolobietolini•50m ago•0 comments

Launch of X (Twitter) API Pay-per-Use Pricing

https://devcommunity.x.com/t/announcing-the-launch-of-x-api-pay-per-use-pricing/256476
1•thinkingemote•50m ago•0 comments

Facebook seemingly randomly bans tons of users

https://old.reddit.com/r/facebookdisabledme/
1•dirteater_•52m ago•1 comments

Global Bird Count Event

https://www.birdcount.org/
1•downboots•52m ago•0 comments

What Is Ruliology?

https://writings.stephenwolfram.com/2026/01/what-is-ruliology/
2•soheilpro•54m ago•0 comments

Jon Stewart – One of My Favorite People – What Now? with Trevor Noah Podcast [video]

https://www.youtube.com/watch?v=44uC12g9ZVk
2•consumer451•56m ago•0 comments

P2P crypto exchange development company

1•sonniya•1h ago•0 comments

Vocal Guide – belt sing without killing yourself

https://jesperordrup.github.io/vocal-guide/
2•jesperordrup•1h ago•0 comments

Write for Your Readers Even If They Are Agents

https://commonsware.com/blog/2026/02/06/write-for-your-readers-even-if-they-are-agents.html
1•ingve•1h ago•0 comments

Knowledge-Creating LLMs

https://tecunningham.github.io/posts/2026-01-29-knowledge-creating-llms.html
1•salkahfi•1h ago•0 comments

Maple Mono: Smooth your coding flow

https://font.subf.dev/en/
1•signa11•1h ago•0 comments

Sid Meier's System for Real-Time Music Composition and Synthesis

https://patents.google.com/patent/US5496962A/en
1•GaryBluto•1h ago•1 comments

Show HN: Slop News – HN front page now, but it's all slop

https://dosaygo-studio.github.io/hn-front-page-2035/slop-news
7•keepamovin•1h ago•2 comments
Open in hackernews

Show HN: Driftcop – Open-source CLI SAST for "MCP rug pull attacks in AI Agents"

https://github.com/sudoviz/driftcop
4•vinaypanghal•6mo ago
Hi HN! We just open-sourced Driftcop, a security tool for people building AI agents with external tools via MCP. Driftcop continuously checks that the tools your AI agent relies on haven’t changed or drifted in unsafe ways. The motivation came from recent findings that AI agents can be quietly compromised via their tools – e.g. a tool that was useful and benign yesterday could auto-update into something malicious today (this is known as a rug pull attack in the MCP context)

Anthropic’s MCP (Model Context Protocol) makes it easy to plug tools into LLMs, but it lacks built-in security checks – in fact, MCP servers can suffer from issues like command injection, permission reuse, and version drift as highlighted by some early research.

What Driftcop does: It’s essentially an AI-aware security scanner and approval workflow:

When you connect your agent to an MCP server (tool provider), Driftcop first saves the approved tool descriptions and metadata.

If anything later changes (the tool’s description, parameters, or underlying version), Driftcop detects that “drift” immediately. It will block the agent from using the changed tool until a human reviews and re-approves it. This stops the AI from blindly running a possibly malicious updated tool. Driftcop also scans tool definitions for obvious red flags (like hidden instructions that could prompt the AI to do unintended actions, aka prompt injection) and checks the tool’s code against a CVE database for known vulnerabilities.

All changes are logged and signed (we integrated with Sigstore to record a transparency log of tool version metadata). So you get an auditable history of what your agent was allowed to use.

In practice, you can run Driftcop as a CLI in your dev/test pipeline or as a service alongside your agent in prod. We provide a web dashboard to visualize tool status (e.g. “Tool X needs re-approval due to changes”). It’s early days – we literally just launched – and we’d love feedback. Why we built this: My co-founder and I encountered multiple scary scenarios while testing agent tools. One example: a harmless-looking text parsing tool that, if fed a certain input, would silently execute an unintended command via the agent – essentially a hidden exploit. It made us realize how little visibility we had into what these third-party tools were actually doing or if they changed over time. We wanted a simple way to enforce a zero-trust approach: trust on first use (with review), then continuously verify. If the tool deviates from its original contract, don’t trust it until you verify again. This is a concept borrowed from traditional supply-chain security, now applied to AI agent tooling.

The project is on GitHub (sudoviz/driftcop) and is Apache-2.0 licensed. We’re keen on making this useful, so issues and PRs are welcome. We also wrote a detailed blog post about “The Rug Pull Problem” in AI agents and our approach here (which I’ll post on Medium/Dev.to soon).

Thanks for reading, and we’re happy to answer questions! Have any of you run into security issues with LLM agents or the MCP ecosystem? We’d love to discuss.

Comments

thamrius•6mo ago
Super excited about this! Thanks for open sourcing the project, will definitely be testing it out this week.