frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: UCP Checker – A manifest debugger for the agentic web

https://ucpchecker.com/extension
1•benjifisher•1h ago

Comments

benjifisher•1h ago
I’ve been frustrated by how opaque agentic commerce is right now. Shopify and Google launched the Universal Commerce Protocol (UCP), but for a developer, it's often a black box in production. You might have your manifest at /.well-known/ucp, but is Gemini actually reading it? Or is it getting silently dropped by a legacy firewall rule?

I built this extension as a lightweight debugger for my own agentic workflows. It’s like Waze for UCP—as we browse, the community is crowdsourcing a map of agent-ready domains. We’ve verified 508 domains so far.

Key features for devs:

Zero-Click Workflow: Uses badge icons to show status instantly (Green = ready, Gray = not detected).

Instant Manifest Debugging: Surfaces HTTP status, response times, and version metadata for UCP manifests.

Gemini Readiness: Checks specifically if the Gemini agent (and others like GPTBot) can reach the store or if they are blocked by robots.txt/WAF rules.

Privacy-First: No tracking, no data selling, and minimal permissions (activeTab only).

You can try it out without an account or signup. I'd love to hear what other signals you'd want to see in the debugger, or if keeping it this lightweight is best!

longtermop•1h ago
This is great — manifest validation feels like the right “static” layer for the agentic web.

One nuance: a lot of prompt-injection / tool-abuse issues happen at runtime, when the agent is consuming untrusted content coming through perfectly “valid” channels (web pages, emails, tool outputs, even responses from allowed domains).

So I like to think: manifests cover the what (permissions / declared capabilities), but you also need something that covers the when — runtime content scanning + policy enforcement before that content is allowed to influence tool calls or sensitive actions.

Curious if you’ve thought about pairing this with runtime guardrails (e.g., classify/strip instructions in fetched content, detect credential exfil patterns, etc.)?

benjifisher•1h ago
Spot on. I see UCP manifests as the "Trust Contract" that defines what is possible, but you're right—contract fulfillment in a non-deterministic environment is where things get messy.

My goal with UCP Checker is to solve the first-order problem: "Is this even a valid endpoint?" You're describing the critical second-order problem: preventing an agent from being hijacked via Indirect Prompt Injection once it actually fetches that content.

I’ve been thinking about this separation of concerns a lot. Ideally, we need a layered approach:

Static Layer (UCP Checker): Validates the schema, capabilities, and reachability.

Runtime Layer: A proxy or sidecar that scans fetched content for "ignore previous instructions" patterns or credential exfiltration attempts before the LLM processes it.

I’d love to hear if you think that "Runtime Guardrail" should live on the merchant side (e.g., a "UCP Shield" gateway) or if it's strictly the responsibility of the Agent/Model provider to sanitize inputs?

Bencher – Continuous Benchmarking

https://github.com/bencherdev/bencher
1•sea-gold•34s ago•0 comments

Show HN: Agent Box – Instant Sandbox VM for Claude Code(Macs)

https://github.com/Zabaca/agent-box
1•uptownhr•45s ago•0 comments

Some Data Should Be Code

https://borretti.me/article/some-data-should-be-code
1•ingve•55s ago•0 comments

DeepSeek R1 new distill models [video]

https://www.youtube.com/watch?v=fFL7la73RO4
1•GTP•1m ago•0 comments

Lockin, a PDF TTS reader for manuals and papers cited Q&A

https://lockin.pageyard.org/
1•lockin__•2m ago•0 comments

How to Make Package Managers Scream (FOSDEM'26)

https://www.youtube.com/watch?v=PBlDHlFnzGo
1•boegel•2m ago•0 comments

A Journey into Understanding the IDE Bus

https://www.crowdsupply.com/polpotronics/picoide/updates/a-journey-into-understanding-the-ide-bus
1•geerlingguy•3m ago•0 comments

There is no evidence for X

2•cadabrabra•4m ago•4 comments

So We Built Our Own Agentic Developer

https://builders.fullscript.com/posts/lessons-learned-from-building-nitro-fullscripts-autonomous-...
2•ncrum•9m ago•0 comments

The Art of Being Lazy(log)

https://www.warpstream.com/blog/the-art-of-being-lazy-log-lower-latency-and-higher-availability-w...
1•ordinarily•10m ago•0 comments

Scientists Discover Life Thriving Beneath Fukushima's Dead Reactors

https://dailygalaxy.com/2026/02/strange-life-under-fukushima-dead-reactors/
1•SunshineTheCat•11m ago•0 comments

Technocracy 2.0

https://brooklynrail.org/2026/02/field-notes/technocracy-2-0/
2•antonomon•14m ago•1 comments

Something Wild Going on with Emails?

2•trevyn•14m ago•0 comments

Home Assistant Comm Badge

https://github.com/graffitiwriter/Home-Assistant-Comm-Badge
1•taubek•14m ago•0 comments

SanDisk crushes wallets with up to 2.8X SSD price hikes

https://www.tomshardware.com/pc-components/ssds/sandisk-crushes-wallets-with-up-to-2-8x-ssd-price...
2•vmykyt•17m ago•0 comments

Start all of your commands with a comma

https://rhodesmill.org/brandon/2009/commands-with-comma/
2•theblazehen•20m ago•0 comments

Sh-DSL – Write/Use Shell with Janet

https://janet-lang.org/spork/api/sh-dsl.html
1•veqq•21m ago•0 comments

Exploring Different Keyboard Sensing Technologies – LTT Labs

https://www.lttlabs.com/articles/2026/01/27/exploring-different-keyboard-sensing-technologies#buc...
1•rbanffy•21m ago•0 comments

Windsurf Tab v2

https://windsurf.com/blog/windsurf-tab-2
1•swyx•21m ago•0 comments

Securely run Claude Code agents in Docker

https://edspencer.net/2026/2/4/run-claude-code-agents-docker-herdctl
1•edspencer•21m ago•0 comments

Hand-Crafting Domain-Specific Compression with an LLM

https://engineering.nanit.com/hand-crafting-domain-specific-compression-with-an-llm-3c42f5c2b070
1•PaulHoule•22m ago•0 comments

The perks of being a mole rat

https://worksinprogress.co/issue/the-perks-of-being-a-mole-rat/
1•ortegaygasset•23m ago•0 comments

Show HN: A TikTok-style research paper reader

https://pokepaper.com/
1•hajimi_hacker•23m ago•0 comments

PaperBanana – Automating Academic Illustration

https://paperbanana.org/
1•bilsbie•24m ago•0 comments

Readr, Safari-Like Reading Mode for Chrome

https://github.com/login
1•ymolodtsov•25m ago•2 comments

GitHub integrates Claude and Codex AI coding agents directly into GitHub

https://github.blog/changelog/2026-02-04-claude-and-codex-are-now-available-in-public-preview-on-...
2•thoughtpeddler•25m ago•1 comments

ClickHouse Agent Skills

https://github.com/ClickHouse/agent-skills
1•clickpiper-pete•26m ago•0 comments

Anthropic's new AI tool: Next black stock market day for the software industry

https://www.heise.de/en/news/Anthropic-s-new-AI-tool-Next-black-stock-market-day-for-the-software...
2•doener•28m ago•1 comments

Ask HN: How can you enforce rules for Claude etc.

1•blackknightdev•29m ago•2 comments

Tell HN: Electrolux HR chief hired to layoff workforce bought 12 room apartment

2•dssadasadsdsa12•30m ago•2 comments