frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: LLM AuthZ Audit – find auth gaps and prompt injection in LLM apps

https://github.com/aiauthz/llm-authz-audit
1•iamspathan•1h ago
Hi HN,

I built llm-authz-audit because I kept seeing the same security issues in LLM-powered applications: API keys hardcoded next to OpenAI calls, FastAPI endpoints serving chat completions with zero auth, user input concatenated straight into prompts, and shared conversation memory with no session isolation.

These aren't hypothetical — they're patterns I found repeatedly across open-source LLM projects and production codebases.

What it does:

It's a static analyzer (think eslint/semgrep but purpose-built for LLM security) that scans Python, JavaScript, and TypeScript codebases for authorization and security gaps. It ships with 13 analyzers and 27 rules covering the OWASP Top 10 for LLM Applications:

- Prompt injection risks (unsanitized input in prompts, missing delimiters) - Hardcoded API keys (OpenAI, Anthropic, HuggingFace, AWS, generic) - Unauthenticated LLM endpoints (FastAPI, Flask, Express) - LangChain/LlamaIndex tools without RBAC - RAG retrievals without document-level access controls - Over-permissioned MCP server configs - Shared conversation memory without user scoping - Missing rate limiting, audit logging, output filtering - Credentials forwarded to LLM via prompt templates Would love feedback from anyone building or securing LLM applications.

Show HN: The Yatima Scale – Measuring civilizations by depth, not energy

https://yatima-scale.netlify.app
1•gillesturpin•43s ago•0 comments

Zero-Knowledge Encryption: A Security Analysis of Cloud-Based Password Managers

https://zkae.io/
1•mlegner•51s ago•1 comments

Monolith – muddying the waters of the digital copyright debate (2011)

https://monolith.sourceforge.net
1•helloplanets•56s ago•0 comments

Google criticizes Europe's plan to adopt free software

https://piefed.zip/c/technology/p/1086069/google-criticizes-europe-s-plan-to-adopt-free-software
1•zoobab•1m ago•0 comments

Forth is just fast Lisp (2017)

https://old.reddit.com/r/Forth/comments/5wsbgr/forth_is_just_fast_lisp/
1•tosh•1m ago•0 comments

Do LLMs hallucinate more in Czech than in English?

https://svana.name/2026/02/do-llms-hallucinate-more-in-czech-than-in-english/
1•msvana•1m ago•0 comments

India orders social media firms to remove unlawful content within three hours

https://www.bbc.com/news/articles/c2lrn8q2q24o
1•thisislife2•7m ago•1 comments

Evolution "Doesn't Need" Mutation. Here's Proof. - Blaise Agüera y Arcas [video]

https://www.youtube.com/watch?v=M2iX6HQOoLg
1•bob1029•7m ago•0 comments

Show HN: Turning web highlights into deterministic Markdown (Sigilla)

1•northerndev•8m ago•0 comments

Ask HN: Do LLM agents need a separate safety layer?

1•amabito•9m ago•0 comments

Show HN: MLX-Ruby – Ruby Bindings for Apple's MLX ML Framework

https://github.com/skryl/mlx-ruby
1•skryl•11m ago•1 comments

OpenClaw Partners with VirusTotal for Skill Security

https://openclaw.ai/blog/virustotal-partnership
1•yoursmanikandan•15m ago•0 comments

Show HN: chowder.dev is a single API for deploying OpenClaw instances

https://www.chowder.dev/
1•egrigokhan•18m ago•0 comments

Parallel Translation at 216x Human Speed

https://www.racecondition.software/blog/parallel-translation/
1•ingve•18m ago•0 comments

Show HN: LockFS is a flexible file-by-file encryption for secure storage

https://github.com/ghost-in-a-jar-00/LockFS
1•0xGhostInAJar•19m ago•0 comments

picol: A Tcl interpreter in 500 lines of code

https://github.com/antirez/picol
2•tosh•20m ago•1 comments

Haloy

https://github.com/haloydev/haloy
1•handfuloflight•22m ago•0 comments

Quando un'impresa di food prova a restituire senso alla città

https://blocknotes.substack.com/p/oltre-i-quattro-canti-la-bottega
1•ilsuddista•22m ago•0 comments

China moves to ban yoke steering wheel after cracking down on flush door handles

https://www.autoblog.com/news/china-moves-to-ban-yoke-steering-wheels-after-cracking-down-on-flus...
2•teleforce•24m ago•0 comments

A Local Directory Browser

https://kaizoku.digital/tools/directory-browser/index.html
1•musti_92•26m ago•0 comments

uxn2

https://git.sr.ht/~rabbits/uxn2
1•tosh•27m ago•0 comments

I learn ML better by seeing it work, so I built visual debuggers

https://stepbyml.com/
1•mkairanbay•31m ago•0 comments

Show HN: FluxDown – Free download manager built with Rust and Flutter

https://fluxdown.zerx.dev
1•zero-lab•33m ago•0 comments

WA small businesses struggle to keep up with health insurance hikes

https://www.seattletimes.com/business/wa-small-businesses-struggle-to-keep-up-with-health-insuran...
1•petethomas•35m ago•0 comments

Aided by AI, Santa Monica broadens hunt for bike and bus lane blockers

https://arstechnica.com/tech-policy/2026/02/santa-monica-deploys-ai-powered-parking-cameras-to-pr...
1•thrawn0r•36m ago•0 comments

Just in Time Software

https://commaok.xyz/ai/just-in-time-software/
1•luu•36m ago•0 comments

How D&D and GM-ing made me a better manager

https://pid.ren/posts/2026-02-15-dnd-and-managing/
1•dethi•43m ago•0 comments

Show HN: Pg-workflows – Lightweight workflows for Node.js using Postgres

https://sokratisvidros.github.io/pg-workflows/
2•sokratisv•44m ago•0 comments

Show HN: Hive: OS Bluesky for Openclaws

https://hive.boats
1•sinned•46m ago•0 comments

Show HN: Gauntlet–Challenge friends to Strava activities with real money (USDC)

https://gauntlet.bet
1•lucidlogic•47m ago•0 comments