frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Aidevshield NPM audit for AI coding tool workflows

https://github.com/aidevshield/aidevshield
1•GrimLabs•1h ago
I built aidevshield, a free open-source security scanner that catches vulnerabilities in AI coding tool configurations things like Cursor, Copilot, and Cline setups.

The problem: AI coding assistants are becoming attack surfaces. In the past year we've seen real exploits:

Clinejection (Dec 2025): Prompt injection via GitHub issue titles → AI triage bot executes shell commands → malicious npm package published to 5M users tj-actions/changed-files (Mar 2025): Tag repointing attack hit 23,000 repos via pull_request_target Shai-Hulud (2025): First self-propagating npm worm using postinstall hooks Rules File Backdoor (Feb 2025): Hidden Unicode characters in .cursorrules for invisible prompt injection Existing tools cover parts of this — Zizmor and actionlint for GitHub Actions, Socket.dev for npm — but nothing scans across all four domains: workflows + AI configs + npm packages + prompt injection.

aidevshield does. One command, zero dependencies beyond js-yaml, fully offline:

npx aidevshield scan . What it detects:

Dangerous GitHub Actions patterns (wildcard users, untrusted event field interpolation, unpinned third-party actions) pull_request_target with untrusted checkout (Pwn Request pattern) Malicious npm lifecycle scripts (postinstall curl | sh, node -e inline exec) Hidden Unicode in AI config files (.cursorrules, .github/copilot-instructions.md) Wildcard tool permissions (Bash(), Edit()) Exposed .env files without .gitignore protection Cache poisoning + credential exposure combos Outputs text, JSON, or SARIF (for GitHub Code Scanning integration).

56 end-to-end tests. Every detection maps to a documented real-world attack.

MIT licensed. No signup, no paywall.

GitHub: https://github.com/aidevshield/aidevshield

Happy to answer questions about the threat landscape or implementation.

Tech titans vow to 'take back' California

https://nypost.com/2026/03/05/us-news/tech-titans-vow-to-take-back-california-from-lefties-call-o...
1•mudil•43s ago•0 comments

First Aptera Solar EV Rolls Off Validation Assembly Line

https://aptera.us/first-vehicle-off-validation-line/
1•TeaVMFan•1m ago•0 comments

Show HN: Yappy – A Python TUI to automate LinkedIn yapping

https://github.com/JienWeng/yappy
2•jienweng•18m ago•0 comments

Shut Up and Take My Money

https://lorendb.dev/posts/shut-up-and-take-my-money/
2•LorenDB•23m ago•0 comments

Spell UI

https://spell.sh/
1•handfuloflight•24m ago•0 comments

Show HN: Swarm – Program a colony of 200 ants using a custom assembly language

https://dev.moment.com/
5•armandhammer10•25m ago•0 comments

Show HN: Custom Search Engine on Safari and Spotlight (macOS)

https://knhash.in/custom-search-engine-on-safari-and-spotlight-macos/
1•knhash•26m ago•0 comments

Show HN: SafeAgent – exactly-once execution guard for AI agents

1•Lions2026•26m ago•0 comments

Enhanced brain cells clear away dementia-related proteins

https://medicalxpress.com/news/2026-03-brain-cells-dementia-proteins.html
2•WaitWaitWha•26m ago•0 comments

Google Patent: Sending Searchers to AI-Generated Pages over Your Site

https://www.seroundtable.com/google-patent-ai-generated-pages-search-41010.html
3•frays•28m ago•0 comments

System76 on Age Verification Laws

https://blog.system76.com/post/system76-on-age-verification/
2•LorenDB•28m ago•0 comments

A Technology for a Low-Trust Society

https://www.theatlantic.com/technology/2026/03/central-lie-prediction-markets/686250/
2•CaptainZapp•31m ago•0 comments

Tollund Man

https://en.wikipedia.org/wiki/Tollund_Man
1•thunderbong•36m ago•0 comments

Show HN: Steadwing – Your Autonomous On-Call Engineer

https://www.steadwing.com/
3•abejith•38m ago•0 comments

Show HN: Verak – Fake Seller Detection for Digital Marketplaces

https://www.verak.io/demo
1•Mikewillcodes•39m ago•0 comments

One Agent SDK – Embed Claude Code in Your App with Codex and Kimi

https://odysa.github.io/one-agent-sdk/
2•agentforce•39m ago•1 comments

Don't Call It 'Intelligence'

https://www.theatlantic.com/ideas/2026/03/intelligence-concept/686121/
2•petethomas•39m ago•0 comments

Parakaryon: The only species with a unknown position in the tree of life

https://en.wikipedia.org/wiki/Parakaryon
1•icwtyjj•39m ago•0 comments

Warden by Sentry

https://warden.sentry.dev/
1•handfuloflight•40m ago•0 comments

Show HN: kg Food Log: Reveal the molecules in your foods

https://kg.enzom.dev/
1•emadda•40m ago•0 comments

On the need for a censorship API for legal compliance in some regions

https://lists.debian.org/debian-legal/2026/03/msg00018.html
2•iamnothere•42m ago•1 comments

Breaking Down 50M Pins: A Smarter Way to Design 3D IC Packages

https://www.allaboutcircuits.com/industry-articles/breaking-down-50-million-pins-a-smarter-way-to...
2•WaitWaitWha•44m ago•0 comments

Show HN: Gluon – Project management with impact-based task prioritization

https://apps.apple.com/us/app/gluon-project-manager/id6758938759
1•cothi•45m ago•3 comments

What I'm learning trying to build a dance theater piece like a startup

1•megbroome•46m ago•0 comments

Ask HN: How common are fake job postings when searching for jobs online?

2•BelVisgarra•49m ago•2 comments

Show HN: Agent-pulse – local gateway that fans out AI agent events to clients

https://github.com/SantiagoBobrik/agent-pulse
1•SantiagoBobrik•50m ago•0 comments

Show HN: Netwall

https://netwall.org
1•dogancan•50m ago•0 comments

Show HN: Collaborative Blogging

https://blog.sgo.to/2026/01/07/how-does-this-blog-work
1•sgoto•52m ago•1 comments

An experiment: funding an independent dance theater piece like a startup

1•megbroome•52m ago•0 comments

Doctronic Is Now Accepting New Patients (and Unsafe Instructions)

https://mindgard.ai/blog/doctronic-is-now-accepting-new-patients-and-unsafe-instructions
1•kierangill•54m ago•0 comments