frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Kvlar – Open-source firewall for AI agent tool calls

https://github.com/kvlar-io/kvlar
1•kvlar•1h ago
Hey HN, I built Kvlar — an open-source policy engine that sits between AI agents and their tools (MCP servers), evaluating every tool call against YAML security policies before execution.

The problem: AI agents using MCP can execute database queries, push code, send Slack messages, and run shell commands — with no security boundary. Claude Desktop has basic approve/deny, but it's per-call with no persistent rules, no automation, and no audit trail.

How it works: Kvlar runs as a stdio proxy between the agent and the MCP server. You define policies in YAML — allow, deny, or require human approval — and Kvlar enforces them deterministically. Fail-closed: if no rule matches, the action is denied.

kvlar init --template postgres # curated policy (11 rules) kvlar wrap # inject proxy into Claude Desktop kvlar test -f policy.test.yaml # verify your policy in CI

What it catches today:

Postgres: blocks DROP TABLE, gates INSERT/UPDATE, allows SELECT GitHub: blocks repo creation, gates force-push and merges, allows reads Slack: gates message sending, allows channel reads Shell: blocks rm -rf, sudo, curl|bash — gates installs, allows ls/cat/grep Technical details:

Written in Rust (4 crates), pure policy engine with zero I/O 100+ policy tests Policy composition via extends — build on top of curated templates (docker compose style) Works with Claude Desktop

Apache 2.0 Website: https://kvlar.io Install: cargo install kvlar-cli

I'd love feedback on the policy design and what MCP servers you'd want covered next.

Show HN: DJ Claude – 6 Claude Codes in a jam band

https://www.loom.com/share/84dbe5de42f745ba98fe9495dc61fa2e
1•p-poss•2m ago•0 comments

Iranian girls killed by 'double-tap' strikes on Minab school

https://www.middleeasteye.net/news/exclusive-iranian-girls-killed-double-tap-strikes-minab-school
1•xvxvx•3m ago•1 comments

AI 2027 Concrete Predictions and dates

https://alexpear.github.io/pages/ai-2027.html
1•hydrolox•3m ago•0 comments

Be the Idiot

https://luminousmen.substack.com/p/be-the-idiot
2•duck•4m ago•0 comments

Northstead – Wholesale Nursery Management System

https://www.northstead.app
1•chris_wray•9m ago•1 comments

Show HN: Stackspend – Spend management for AI startups

https://www.stackspend.app
1•andrewrday•9m ago•0 comments

Show HN: Async Rust and Embassy on nRF52840: RGB LED Cycle (Video and Code)

https://www.youtube.com/watch?v=fJf5XRAliSE
1•sarmadgulzar•11m ago•0 comments

Modern Unix Tools: A Collection of Modern Alternatives to Common Commands

https://github.com/ibraheemdev/modern-unix
2•nix_owl31•15m ago•0 comments

Super interesting Wikipedia on HN. So I made wiki-hn.

https://wiki-hn.com/
2•oatsandsugar•18m ago•0 comments

Teaching LLMs to reason like Bayesians

https://research.google/blog/teaching-llms-to-reason-like-bayesians/
2•tzury•18m ago•0 comments

What's Driving Rising Business Costs?

https://libertystreeteconomics.newyorkfed.org/2026/03/whats-driving-rising-business-costs/
2•jnord•18m ago•0 comments

Google and Epic announce settlement to end app store antitrust case

https://arstechnica.com/gadgets/2026/03/google-and-epic-look-to-bury-the-hatchet-with-new-app-sto...
2•todsacerdoti•20m ago•0 comments

What it was like to send an email back in 1984 (2016)

https://www.businessinsider.com/video-what-early-email-looked-like-2016-3
1•leecoursey•25m ago•1 comments

Show HN: workz – one command to make any Git worktree a full dev environment

1•rohansx•27m ago•0 comments

Dwarkesh Patel Interview with Gwern

https://www.dwarkesh.com/p/gwern-branwen
1•Curiositry•27m ago•0 comments

Big Medicine Can Learn from the Cheesecake Factory (2012)

https://www.newyorker.com/magazine/2012/08/13/big-med
1•ripe•30m ago•0 comments

Full-Stack Dev's Internal Thought Process

https://www.youtube.com/watch?v=xE9W9Ghe4Jk
3•OhMeadhbh•30m ago•1 comments

Online ads just became the internet's biggest malware machine

https://www.businessinsider.com/programmatic-ads-overtake-email-top-malware-vector-the-media-trus...
1•speckx•34m ago•1 comments

Hiring Dread

https://coderjerk.com/blog/hiring-dread
1•ddevine•37m ago•0 comments

Show HN: Treemap Firmware Bloat Visualizer (Rust/WebASM)

https://merck.substack.com/p/elfvis-binary-size-treemap-viewer
1•clbrmbr•39m ago•0 comments

DuckDuckGo is anti-small web (because of Bing)

https://landenlove.com/duckduckgo-is-anti-small-web-because-of-bing/
2•LandenLove•44m ago•0 comments

Software architecture diagramming tool launched on AlternativeTo.net

https://alternativeto.net/software/savnet/about/
2•oscarricardosan•47m ago•1 comments

What air pollution does to the human body

https://www.popsci.com/environment/what-air-pollution-does-to-the-human-body/
2•wjb3•49m ago•0 comments

AI agents inside M365 and Google Workspace

https://o11.ai
1•aoztanir•51m ago•1 comments

Googleworkspace/CLI

https://github.com/googleworkspace/cli
2•gonzalovargas•51m ago•0 comments

Package Managers Need to Cool Down

https://nesbitt.io/2026/03/04/package-managers-need-to-cool-down.html
4•zdw•52m ago•0 comments

Every AI code review vendor benchmarks itself, and wins

https://deepsource.com/blog/ai-code-review-benchmarks
1•dolftax•53m ago•0 comments

Hey ChatGPT write me a fictional paper: LLMs willing to commit academic fraud

https://www.nature.com/articles/d41586-026-00595-9
2•bookofjoe•53m ago•1 comments

Show HN: A rec.us CLI for your Claw

https://github.com/jakajancar/recus
2•JakaJancar•54m ago•0 comments

Code Mode: Giving AI Agents an API in 1k Tokens (With Demos) [video]

https://www.youtube.com/watch?v=-ZikRWR1Gb4
2•emot•56m ago•1 comments