frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Armor1 – Risk Analysis Database of Every MCP Server

https://mcp.armor1.ai/mcp-directory
6•razuba•1h ago
Hi HN, I'm the co-founder of Armor1. We’re building security tooling around agentic AI systems.

Today, we're releasing our public MCP catalog with detailed risk analysis for every MCP server we've found on the internet: https://mcp.armor1.ai/mcp-directory

We all love agents and the power that MCPs unlock: suddenly your AI assistant can query databases, manage files, call APIs, and interact with the real world. But when we started adopting MCPs ourselves, we kept running into the same nagging questions:

Is this MCP safe? Where is my data actually going? Could it execute destructive actions? Is it susceptible to prompt injection? Can the LLM be tricked into calling something it shouldn't? And perhaps most concerning, can one MCP server influence the model and exfiltrate data meant for another?

We looked for answers and found... not much. No comprehensive catalog or standardized risk assessment. Nothing that gave us confidence before connecting an MCP to our agents.

So we built an MCP threat catalog and what we found was eye-opening.

We built what we believe is the deepest risk analysis pipeline for MCP servers:

• Provenance tracking: from an official source or community-contributed

• MCP spec conformance: does it follow the protocol correctly, or are there deviations that could cause unexpected behavior

• OWASP Top 10 for Agentic Apps: evaluate tool descriptions against the emerging threat categories specific to AI agents

• Static source analysis: analyze source code for AI-specific vulnerabilities, not just traditional ones

• CVE correlation: check dependencies against known vulnerabilities.

• Behavioral risk patterns: tool definitions that could enable prompt injection, privilege escalation, or cross-server data theft

What we found:

• Hundreds of credential leaks: API keys, tokens, and secrets exposed in server configurations and code.

• Dozens of MCP servers using known malicious packages: Not just vulnerable dependencies, but actually malicious ones.

• Tools attempting context poisoning: MCP servers designed to subvert the LLM and steal information via memory manipulation, potentially exfiltrating data meant for other connected servers.

We want everyone to realize the benefits of agentic AI, but not at the cost of security being an afterthought. So we're making this catalog free with no login, and we're committed to keeping it that way.

This is still a WIP. Looking forward to your feedback on what we need to improve, what we got right, and what we should prioritize next.

Show HN: Turn messy financial spreadsheets into structured data

https://novasheets.com/
1•gauravsc•1m ago•0 comments

Improving My Data Transformations

https://github.com/Hyperwindmill/morphql
1•hyperwindmill•1m ago•1 comments

Handing My Daily Tasks Off to Claude Code

https://theautomatedoperator.substack.com/p/handing-my-daily-tasks-off-to-claude
2•idopmstuff•4m ago•0 comments

Claude Skills for Marketing

https://maestrix.ai/skills
1•guidum80•6m ago•0 comments

Micropay: Stripe-like payment intents for M-Pesa with no transaction fees

https://micropay.dev/
1•possiblelion•7m ago•1 comments

Heritability of life span is about 50% when heritability is redefined

https://dynomight.net/lifespan/
2•csours•8m ago•1 comments

Rules Create Unequal Rewards: Tennis Players Allocate Resources Efficiently

https://arxiv.org/abs/2601.15327
1•PaulHoule•9m ago•0 comments

The Promises of 'High-Assurance' Cryptography

https://symbolic.software/blog/2026-02-05-cryspen/
1•todsacerdoti•9m ago•0 comments

Germany to require streaming platforms to invest in local production

https://www.reuters.com/business/retail-consumer/germany-require-streaming-platforms-invest-local...
1•giuliomagnifico•9m ago•0 comments

'Orwellian' incident in supermarket using facial recognition tech

https://www.theguardian.com/technology/2026/feb/05/london-man-sainsburys-facial-recognition-facew...
2•graemep•10m ago•0 comments

Adding Canada Back to Our List of Accepted Countries of Incorporation

https://www.ycombinator.com/blog/adding-canada-back/
2•todsacerdoti•11m ago•0 comments

Whack-a-mole: US academic (John Mearsheimer) fights to purge his AI deepfakes

https://techxplore.com/news/2026-02-whack-mole-academic-purge-ai.html
1•bikenaga•12m ago•0 comments

Anthropic can win in consumer by being more open

https://sergey.substack.com/p/how-anthropic-can-win-in-consumer
2•neural_thing•12m ago•0 comments

Show HN: Relai – Share context between AI assistants, 100% local

https://github.com/kirillpolevoy/relai
1•kpolevoy1•15m ago•0 comments

Show HN: Messaging for AI agents without SMTP, MIME, or polling inboxes

https://getrelay.sh/
1•juansgaitan•15m ago•0 comments

Question of Cursor AI Movement

1•matinplace•15m ago•0 comments

Hypernetworks: Neural Networks for Hierarchical Data

https://blog.sturdystatistics.com/posts/hnet_part_I/
1•mkmccjr•17m ago•0 comments

Stephenson Impersonator; Minor Update

https://nealstephenson.substack.com/p/stephenson-impersonator-minor-update
1•pcfwik•19m ago•0 comments

What Is Ruliology?

https://writings.stephenwolfram.com/2026/01/what-is-ruliology/
2•surprisetalk•19m ago•0 comments

Draft Emoji List for 2026/2027

https://blog.emojipedia.org/draft-emoji-list-for-2026-2027/
1•surprisetalk•19m ago•0 comments

Free WordArt Generator – Create 90s Text Effects Online

https://www.makewordart.com
1•surprisetalk•19m ago•0 comments

There aren't enough smart people in biology doing something boring (2024)

https://www.owlposting.com/p/there-arent-enough-smart-people-in
1•surprisetalk•19m ago•0 comments

Using the Dell Pro Max with GB10 to profit within 12 months

https://www.servethehome.com/using-the-dell-pro-max-with-gb10-to-profit-within-12-months-nvidia/
1•teleforce•19m ago•0 comments

Sam Altman got exceptionally testy over Claude Super Bowl ads

https://techcrunch.com/2026/02/04/sam-altman-got-exceptionally-testy-over-claude-super-bowl-ads/
2•Signez•19m ago•1 comments

The world is more equal than you think

https://www.economist.com/graphic-detail/2026/02/03/the-world-is-more-equal-than-you-think
1•ksec•19m ago•1 comments

Where did the tips go? Restaurants say thousands missing from Everyday Payments

https://globalnews.ca/news/11652795/tips-bc-restaurants-thousands-missing-third-party-account/
1•cf100clunk•19m ago•0 comments

Researchers tested AI against 100k humans on creativity

https://www.sciencedaily.com/releases/2026/01/260125083356.htm
1•amichail•20m ago•0 comments

Dell Pro Max with GB10 is paying for itself [video]

https://www.youtube.com/watch?v=ib913zfNh7I
1•teleforce•20m ago•0 comments

Modernizing Linux swapping: the end of the swap map

https://lwn.net/SubscriberLink/1057102/7fd73b5dad297481/
3•chmaynard•21m ago•0 comments

Clankers with Claws

https://world.hey.com/dhh/clankers-with-claws-9f86fa71
1•ksec•22m ago•0 comments