frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

We audited both MCP SDKs – three classes of boundary-crossing vulnerabilities

1•manuelnd•2h ago
MCP (Model Context Protocol) has 77k+ stars and is becoming the standard way AI agents connect to tools. We audited both official SDKs (TypeScript and Python) at the source code level and found three classes of boundary-crossing vulnerabilities.

All three confirmed with live PoC exploits using the SDK's real auth components (BearerAuthBackend, RequireAuthMiddleware, TokenVerifier).

Findings:

1. Tool Capability Shadowing — tool names are flat strings with no namespace or origin tracking. If two servers register "read_data", one silently wins. We validated against gpt-5-nano: the model made path traversal and credential exfiltration tool calls that would route to an attacker's shadow server. 10/10 genuine, 0% FP.

2. Token Audience Confusion — verify_token() takes one parameter: the token string. No expected audience. A read-only token for Server A works on Server B's admin_delete endpoint. This isn't an implementation bug — it's a gap in the SDK interface. Every MCP server built on these SDKs inherits this.

3. Stale Authorization — no push invalidation mechanism. Revoked tokens accepted for the full cache TTL. Scope downgrades invisible until cache expires. In production with 5-minute caches, that's a 5-minute window. JWT-only validation (no introspection) is worse: no revocation possible until the token itself expires (hours to days).

The combined chain: enumerate tools (no namespace isolation) → shadow a tool (silent routing) → escalate privileges (cross-server token) → persist after detection (cache TTL).

Additional finding: smaller models are dramatically more exploitable. gpt-5-nano: 100% genuine rate on tool abuse. gpt-5.2: ~45%. The model most likely used in cost-sensitive deployments is the most vulnerable to attacks the architecture fails to prevent.

What's well-implemented: filesystem path validation, git injection prevention, OAuth 2.1 with PKCE, tool input validation. The vulnerabilities are in the boundaries between servers.

Total cost of all scanner runs: $2.83.

Full report: https://tachyonicai.com/blog/mcp-security-audit/ Taxonomy (open source, 122 attacks): https://github.com/tachyonicai/tachyonic-heuristics

Researchers build ultra-efficient optical sensors shrinking light to a chip

https://www.colorado.edu/ecee/researchers-build-ultra-efficient-optical-sensors-shrinking-light-chip
1•giuliomagnifico•33s ago•0 comments

Builders Unscripted: Ep. 1 – Peter Steinberger, Creator of OpenClaw

https://www.youtube.com/watch?v=9jgcT0Fqt7U
1•doppp•37s ago•0 comments

Homeownership Is Out of Reach for Many Americans, Despite a Buyer's Market

https://www.nytimes.com/2026/02/23/business/home-buying-market-real-estate-economy.html
1•mooreds•55s ago•0 comments

Show HN: SQL Crack – Local-first SQL visualizer with column lineage

https://github.com/buva7687/sql-crack
1•buva•1m ago•0 comments

Nimble gets $75M to build web datasets for AI agents

https://twitter.com/nimble_data/status/2026288589735403716
1•blef•1m ago•0 comments

Time to Move On – The Reason Relationships End

https://steveblank.com/2026/02/24/time-to-move-on-the-reason-relationships-end/
1•MindGods•2m ago•0 comments

The Day Moltbook's Agents Started Doing SEO

https://growtika.com/blog/the-day-moltbooks-agents-started-doing-seo
1•Growtika•2m ago•0 comments

Be Careful with LLM "Agents"

https://maurycyz.com/misc/sandbox_llms/
1•speckx•3m ago•0 comments

Nobody Wants to Use Your Software (and That's the Point)

https://www.runproper.com/blog/nobody-wants-to-use-your-software
1•rsanaie•4m ago•0 comments

The Agent Times: OpenHands hits 68K stars in the agent economy

https://theagenttimes.com/articles/68107-stars-is-openhands-the-rocket-fuel-the-agent-economy-needs
1•Ross00781•5m ago•0 comments

Cardiorespiratory fitness is associated with lower anger and anxiety

https://linkinghub.elsevier.com/retrieve/pii/S000169182600171X
2•PaulHoule•5m ago•1 comments

Free Font: Times New Resistance

https://www.abbyhaddican.com/times-new-resistance
3•AlexandrB•5m ago•0 comments

EU: ECR rapporteur Wiśniewska is fighting to EXTEND scanning of private messages

https://digitalcourage.social/@echo_pbreyer/116119256928189485
1•nickslaughter02•6m ago•0 comments

Show HN: If Discord, Reddit, X, IRC and 4chan had a baby

1•ignasheahy•6m ago•0 comments

Replacing Anthropic's API with 2x 3090s. Claude Code on a local 80B Qwen model

https://twitter.com/sudoingX/status/2026297110141018122
1•ianlpaterson•6m ago•0 comments

Japan Pushes to Make Snowball Fighting an Olympic Event

https://www.chosun.com/english/sports-en/2026/02/24/H67UMP7OSNE7NOB6XR2JX4W7KY/
1•woldemariam•6m ago•0 comments

Show HN: Digital Janitor – A 1-click Python script to auto-sort messy downloads

https://github.com/Radhesh20/digital-janitor
1•radhesh20•7m ago•0 comments

Tell HN: GitHub Actions is falling over again

1•drcongo•8m ago•0 comments

Tethered – Runtime network egress control for Python

https://github.com/shcherbak-ai/tethered
1•sergiishcherbak•8m ago•1 comments

The New Panopticon: How AI Changes Accountability

https://florinandrei.substack.com/p/the-new-panopticon-how-ai-changes
1•Florin_Andrei•8m ago•1 comments

Racket 9.1 Is Available

https://blog.racket-lang.org/2026/02/racket-v9-1.html
2•owl_vision•9m ago•0 comments

Bulgarian Teacher with 38 International Medalist Students

https://www.youtube.com/watch?v=Zn0ZVxHGFC0
1•dzink•9m ago•0 comments

USRP X420 10MHz – 20 GHz SDR

https://www.ni.com/en-us/shop/model/ettus-usrp-x420.html
1•fadedsignal•10m ago•0 comments

Is AI Good for Democracy?

https://www.schneier.com/blog/archives/2026/02/is-ai-good-for-democracy.html
1•speckx•10m ago•0 comments

Show HN: Open-source LLM and dataset for sports forecasting (Pro Golf)

https://huggingface.co/LightningRodLabs/Golf-Forecaster
5•bturtel•10m ago•0 comments

PersonaLive Expressive Portrait Image Animation for Live Streaming

https://arxiv.org/abs/2512.11253
1•tamnd•10m ago•0 comments

People Are Worried About Blue Owl Liquidity

https://www.bloomberg.com/opinion/newsletters/2026-02-23/people-are-worried-about-blue-owl-liquidity
1•mooreds•10m ago•1 comments

The Epstein Files Should Never Have Been Released

https://www.nytimes.com/2026/02/23/opinion/epstein-files-justice-department.html
3•Anon84•12m ago•0 comments

Show HN: Ghist – Task management that lives in your repo

https://github.com/unnecessary-special-projects/ghist
2•nxnze•13m ago•0 comments

Elektrobit and Mobileye partner on safety Linux for L4 autonomy

https://www.just-auto.com/news/elektrobit-and-mobileye-collaborate-on-safety-linux-for-level-4-au...
1•losgehts•14m ago•0 comments