frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Setting Boundaries: Getting Zero-Trust Tool Calling Right for Agentic AI

https://www.macawsecurity.com/blog/zero-trust-tool-calling-for-agentic-AI
1•mrajagopalan•1h ago

Comments

mrajagopalan•1h ago
Following the MCP security discussion -https://news.ycombinator.com/item?id=45199713

I've written up our approach to securing AI tool calling through cryptographic enforcement rather than prompt engineering.

The core problem: we're mixing control and data planes without security boundaries. When an LLM with tool access processes untrusted input, you get intent hijacking, tool chaining, and context poisoning. The LLM fundamentally cannot be the boundary - it's trained to follow instructions, not evaluate them.

The insight: treat every AI entity like an untrusted network service. We give LLMs, tools, and agents cryptographic identities and enforce policies at tool boundaries (where the actual damage happens). This creates an "Authenticated Workflows" pattern - like mTLS but for AI interactions.

Intent is signed before the LLM sees it. Tools verify signatures independently. Policies are cryptographically bound to invocations. Even if the LLM is completely confused by prompt injection, it can't forge these signatures.

We've validated this with SecureOpenAI and SecureMCP implementations that block injections that would otherwise succeed. The challenge was making it transparent to developers - they just call tool(params) while security happens underneath.

Blog post with technical details: https://www.macawsecurity.com/blog/zero-trust-tool-calling-f...

Would love feedback from anyone building production AI systems. Are others seeing these attack vectors in the wild? How are you approaching defense?

AI False information rate for news nearly doubles in one year

https://www.newsguardtech.com/ai-monitor/august-2025-ai-false-claim-monitor/
1•hydrox24•1m ago•0 comments

Prion

https://en.wikipedia.org/wiki/Prion
1•downboots•4m ago•0 comments

The coming war on general computation (2011) [video]

https://www.youtube.com/watch?v=HUEvRyemKSg
1•akersten•16m ago•1 comments

Simple referral cards to turn intros into meetings

https://www.getquickintro.com
1•kez_•24m ago•1 comments

YouTube Thumbnail Downloader

https://youtube.tools100.online/
1•chinesenamenow•27m ago•0 comments

A Strange Gas-Pumping Defect Is Making $100k Corvettes Go Up in Flames

https://www.wsj.com/business/autos/a-strange-gas-pumping-defect-is-making-100-000-corvettes-go-up...
2•bookofjoe•31m ago•1 comments

Cwt.cam – Jwt.io for CBOR Web Tokens

https://cwt.cam
2•dtkav•31m ago•0 comments

What 3 Topics

https://what3topics.pages.dev/
1•CalmhostAcct•31m ago•0 comments

Calendar Pro for Obsidian

https://lifeos.vip/plugin/calendar/calendar-pro.html
1•quanru•33m ago•0 comments

Neural anticipation of virtual infection triggers an immune response

https://www.nature.com/articles/s41593-025-02008-y
1•walterbell•37m ago•0 comments

3 Phase AI coding workflow Demostration

https://old.reddit.com/r/ClaudeCode/comments/1nh75k2/3_phase_workflow_demonstration_with_aider_us...
1•faangguyindia•40m ago•0 comments

Rebutting 33 False Claims About Solar, Wind, and Electric Vehicles

https://scholarship.law.columbia.edu/cgi/viewcontent.cgi?article=1218&context=sabin_climate_change
20•toomuchtodo•42m ago•4 comments

Praxos – AI assistant that does things for you

https://www.mypraxos.com/
2•MasoudKP•48m ago•3 comments

Patient-reported treatment outcomes in ME/CFS and long Covid

https://www.pnas.org/doi/10.1073/pnas.2426874122
2•walterbell•51m ago•0 comments

An Evaluation of the Effectiveness of Chrome's CRLSets

https://www.grc.com/revocation/crlsets.htm
1•sugarpimpdorsey•52m ago•0 comments

CURE ID: Share and Explore Treatment Experiences

https://cure.ncats.io
1•walterbell•53m ago•0 comments

Amazon's Zoox jumps into U.S. robotaxi race with Las Vegas launch

https://www.cnbc.com/2025/09/10/amazons-zoox-jumps-into-us-robotaxi-race-with-las-vegas-launch-.html
3•gmays•56m ago•1 comments

Argumentum ad colossum

https://chrisdone.com/posts/argumentum-ad-colossum/
2•dmarto•1h ago•1 comments

J-Link RTT for the Masses using Semihosting on ARM

https://bogdanthegeek.github.io/blog/insights/jlink-rtt-for-the-masses/
7•kristianp•1h ago•0 comments

'Let's understand the value of the forest' says Liberia's Silas Siakor

https://news.mongabay.com/2025/09/lets-understand-the-value-of-the-forest-says-liberias-silas-sia...
1•PaulHoule•1h ago•0 comments

California Wants to Ban 'Forever Chemicals' in Pans. These Chefs Say Don't Do It

https://www.nytimes.com/2025/09/12/climate/rachael-ray-david-chang-pfas-forever-chemicals-cookwar...
4•voxadam•1h ago•1 comments

Show HN: PaperSync, making ArXiv papers collaborative

https://hackcmu25.vercel.app/
2•qflop•1h ago•1 comments

I Like 669 Better

https://datastream.substack.com/p/i-like-669-better
3•racketracer•1h ago•1 comments

Phone batteries are getting more compact, but the US is missing out

https://www.theverge.com/the-stepback-newsletter/776517/silicon-carbon-batteries-phones
9•nradov•1h ago•4 comments

The Trauma You Need to Learn

https://staysaasy.com/management/2025/09/14/educational-trauma.html
4•thisismytest•1h ago•0 comments

Kathy Hochul: Why I Am Endorsing Zohran Mamdani

https://www.nytimes.com/2025/09/14/opinion/hochul-endorsement-mamdani.html
6•yurivish•1h ago•1 comments

Malaysia reins in data centre growth, complicating China's AI chip access

https://www.reuters.com/world/china/malaysia-reins-data-centre-growth-complicating-chinas-ai-chip...
1•ilamont•1h ago•0 comments

Cognitive and Gestalt psychology in your code: SMVP pattern

https://github.com/sl8s/smvp/tree/v1.0.0
1•sl8s•1h ago•0 comments

Slidebee – turn any ArXiv paper into a presentation

https://slidebee.genmini.ai/
3•surreal_•1h ago•1 comments

Citizens Beacon Platform Development

1•CitiznesBeacon•1h ago•0 comments