frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: AgentSecrets – Zero-Knowledge Credential Proxy for AI Agents

https://github.com/The-17/agentsecrets
2•steppacodes•1h ago
After seeing 8,000+ MCP servers exposed this month and the OpenClaw/ClawHavoc campaign compromise 30,000+ instances, I built a proxy that keeps credentials in the OS keychain. The agent makes authenticated API calls but never sees the key values.

The core insight: AI agents are users, not applications. Applications need credential values to authenticate. Agents just need to make authenticated calls. Those are different things.

AgentSecrets sits between the agent and the upstream API. The agent says "use STRIPE_KEY". The proxy resolves the real value from the OS keychain, injects it into the request at the transport layer, and returns only the response. The key never enters agent memory.

Technical details: -Local HTTP proxy on localhost:8765 with session token (blocks rogue processes on same machine) -OS keychain backed — macOS Keychain, Linux Secret Service, Windows Credential Manager -6 injection styles: bearer, basic, custom header, query param, JSON body, form field -SSRF protection blocking private IPs and non-HTTPS targets -Redirect stripping — auth headers not forwarded on redirects -JSONL audit log — key names only, no value field in the struct, structurally impossible to log values -MCP server for Claude Desktop and Cursor -Native OpenClaw skill -Global storage mode config — set keychain-only once during init, applies everywhere

Honest limitations: if a malicious skill has independent network access outside AgentSecrets it can still make its own calls. This removes credentials as an attack surface specifically, not every attack surface.

For the specific attack that just hit 30,000 OpenClaw users — a malicious skill exfiltrating plaintext credentials — it is structurally prevented. The keys were never on the filesystem. MIT, open source.

Comments

gauravguitara•1h ago
Interesting we both posted absolutely at the same time for the exact same problem. https://news.ycombinator.com/item?id=47167671 I've built a token exchange using RFC 8693.
verdverm•21m ago
This defines Show HN right now, so many people using AI to throw together their next best shot at making it big. The code was never the bottle neck, it's something every one of these submissions is not seeing

Show HN: Depwire – Dependency graph and MCP tools so AI stops refactoring blind

https://github.com/depwire/depwire
1•atefataya•1m ago•0 comments

Show HN: Claude/Gemini/Codex 10-100x faster with pandō (CAD for code)

https://getpando.ai/
1•george_ciobanu•1m ago•1 comments

SynthID

https://deepmind.google/models/synthid/
2•tosh•4m ago•0 comments

Show HN: EK-1 – A local-first, sovereign AI agent built in Go and Rust

https://egokernel.com
1•felixche•4m ago•0 comments

Pacific Fusion finds a cheaper way to make its fusion reactor work

https://techcrunch.com/2026/02/05/pacific-fusion-finds-a-cheaper-way-to-make-its-fusion-reactor-w...
2•PaulHoule•6m ago•0 comments

Hanging with news-free friends preserves my sanity in a chaotic world

https://theishything.bearblog.dev/i-have-been-hanging-out-with-people-who-dont-watch-the-news/
1•speckx•6m ago•0 comments

NutriAI

https://nutriai.si/
1•domaisi•7m ago•1 comments

Claude Code Mexico breach: training safety failed ground truth layer

https://github.com/Mysticbirdie/hallucination-elimination-benchmark
1•MysticBirdie•8m ago•2 comments

Ask HN: Solo Founder Questions

1•newbeeguy•8m ago•0 comments

The Wrong Apocalypse [pdf]

https://ionanalytics.com/wp-content/uploads/2026/02/The_Wrong_Apocalypse.pdf
1•simonebrunozzi•8m ago•0 comments

New research: Nighttime road traffic noise stresses the heart and blood vessels

https://www.escardio.org/news/press/press-releases/new-research/
1•josephcs•9m ago•0 comments

Show HN: I built an open-source analytics platform for Claude Code sessions

https://github.com/ConfabulousDev/confab-web
1•jjak82•12m ago•0 comments

People living in UK's poorest areas have less diverse gut bacteria, study finds

https://www.theguardian.com/society/2026/feb/24/people-living-in-uks-poorest-areas-have-less-dive...
2•beardyw•12m ago•0 comments

Housing: Rent vs. Buy Calculator Spreadsheet

https://longviewy.com/rent-vs-buy-spreadsheet-using-five-key-inputs/
1•josephcs•13m ago•0 comments

I built a 151k-node GraphRAG swarm that autonomously invents SDG solutions

1•wisdomagi•13m ago•0 comments

Regex is dead. We replaced it

https://matchlang.com
2•hollowsolve•15m ago•5 comments

OpenaAI: Disrupting malicious uses of our models [pdf]

https://cdn.openai.com/pdf/df438d70-e3fe-4a6c-a403-ff632def8f79/disrupting-malicious-uses-of-ai.pdf
1•defly•16m ago•0 comments

The age of flat pack code

https://ilearnt.com/blog/flatpackcode/
1•speckx•16m ago•0 comments

Ralph Wiggum Explained: Stop Telling AI What You Want – Tell It What Blocks You

https://platform.uno/blog/ralph-wiggum-explained-stop-telling-ai-what-you-want-tell-it-what-block...
1•e12e•17m ago•0 comments

Show HN: Relay – SMS API for developers (send your first text in 2 min)

1•danielkdewar•18m ago•0 comments

Adonisjs v7 released (Next.js alternative)

https://adonisjs.com/blog/v7
1•danfritz•18m ago•0 comments

You Just Need Postgres

https://youjustneedpostgres.com/
2•olucasandrade•18m ago•1 comments

Show HN: A minimal Claude Code clone written in Rust

https://github.com/keon/mini-claude-code
1•kwk236•20m ago•0 comments

Typing Fun Game

https://kwerty.site
1•soexya•21m ago•0 comments

Smartphones, Online Music Streaming, and Traffic Fatalities

https://www.nber.org/papers/w34866
1•speckx•21m ago•0 comments

Secria Mobile – Post-quantum encrypted email, now on iOS and Android

https://secria.me
1•adrianmav•22m ago•1 comments

Show HN: 20x – Open-source agent orchestrator for Linear/HubSpot tasks

https://github.com/peakflo/20x
2•dmitryv•23m ago•0 comments

Nobody Trusts Anybody Anymore

https://yourbrainonmoney.substack.com/p/low-trust-society-cost
1•lemonberry•23m ago•0 comments

Tell HN: YouTube Subscription page is being deprecated

3•csours•24m ago•2 comments

Any Open Source Contributors?

https://github.com/Shantanugupta43/SuggestPilot
1•shaanuknow•26m ago•1 comments