frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

JadeGate – A deterministic safety proxy for MCP servers (no LLMs)

1•coolcoder9520•1h ago
Integrating an MCP server into Claude or Cursor right now is essentially running curl | bash from a stranger. I found tools claiming to be "weather checkers" that basically have unprompted, silent access to read ~/.ssh/ or environment variables.

This isn't a bug; the MCP protocol currently just has zero security boundaries.

Letting an LLM decide if a tool is safe is like asking a suspect to write their own police report. So I spent the last few weeks building JadeGate—an open-source, transparent proxy. It uses deterministic math and static analysis instead of AI:

Policy Engine: Strict allow/deny per tool.

Call-Chain Tracking: Stops rogue recursive calls via DAG verification.

Transparent: Wraps the servers without changing your workflow.

GitHub Repo: https://github.com/JadeGate/jade-core Website: https://jadegate.io/

Our philosophy: You can't use a probabilistic tool to reliably audit another probabilistic tool. Instead, we treat an agent's skill like source code and apply the same deterministic static analysis used in compilers to prove its safety boundaries before it ever runs.

We are using BSL 1.1 converting to Apache 2.0. Would love any feedback on the static analysis approach!

Comments

coolcoder9520•1h ago
OP here. Happy to answer any technical questions about the implementation, especially around the static analysis of the call-graph (DAG) or the BSL 1.1 license choice.

(I also have a GIF demo of it blocking a malicious tool in real-time if anyone is interested, but didn't want to clutter the main post).

Show HN: I Was Here – Draw on street view, others can find your drawings

https://washere.live
1•mrktsm__•1m ago•0 comments

Prevent duplicate webhook executions in n8n (template)

https://github.com/aari-ai/n8n-webhook-idempotency
1•neshkito•6m ago•1 comments

United States Leads Dismantlement of One of the Largest Hacker Forums

https://www.justice.gov/opa/pr/united-states-leads-dismantlement-one-worlds-largest-hacker-forums
1•mikhael•7m ago•0 comments

Show HN: LLM Sycophancy Benchmark: Opposite-Narrator Contradictions

https://github.com/lechmazur/sycophancy
3•zone411•14m ago•0 comments

Windows: Microsoft broke the only thing that mattered

https://www.yankodesign.com/2026/03/08/microsoft-broke-the-only-thing-that-actually-mattered/
4•kjellsbells•16m ago•0 comments

Language Birth

https://asteriskmag.com/issues/13/language-birth
1•mitchbob•17m ago•1 comments

Show HN: Consul – AI Executive Assistant

https://consul.so
1•goldkey•17m ago•0 comments

Show HN: Mach9 Poker Beta

https://mach9poker.com/beta/
1•ChicagoDave•22m ago•0 comments

Battery Test [video]

https://www.youtube.com/watch?v=RGGHyY2mN7o
1•fenced_load•22m ago•0 comments

Times New Roman drawn from memory (1 hour timelapse)

https://old.reddit.com/r/typography/comments/1rodacl/times_new_roman_drawn_from_memory_1_hour_tim...
1•johnnyApplePRNG•23m ago•0 comments

Build your OpenClaw superstack under a minute

https://better-openclaw.dev
1•diopisemou•27m ago•1 comments

Why the US Could Blame AI for Blowing Up the Iranian School

https://www.jonathanbennion.info/p/why-the-us-may-blame-ai-for-blowing
1•rooftopzen•30m ago•1 comments

Do developers have agency? A study of 66k GitHub projects (7.3TB)

https://link.springer.com/article/10.1007/s44427-025-00019-y
1•ekrisza•30m ago•1 comments

Appsflyer SDK Hijacked

https://websdk.appsflyer.com/
2•jackyzhao•34m ago•2 comments

Annotating for Agents

https://benji.org/annotating
1•parksb•35m ago•0 comments

How curl Started [video]

https://www.youtube.com/watch?v=ohzzGy5K9Dk
1•serialport•35m ago•1 comments

Show HN: Claude Code Token Elo

https://www.clauderank.com
1•ymaws•36m ago•0 comments

Pwning NetBSD-Aarch64 (ARM)

https://www.feyrer.de/NetBSD/bx/blosxom.cgi/nb_20260308_1932.html
1•jaypatelani•36m ago•0 comments

Moment of Zen compilation from daily show

https://www.youtube.com/watch?v=-4OTAXzliUA
1•marysminefnuf•37m ago•0 comments

Htmx skill that includes everything

https://skills.sh/damusix/skills/htmx
1•daniloa•39m ago•1 comments

Karl Rove on Iraq War (2009)

https://www.youtube.com/watch?v=f1mTqVSqvvU
1•marysminefnuf•43m ago•0 comments

Emacs and Vim in the Age of AI

https://batsov.com/articles/2026/03/09/emacs-and-vim-in-the-age-of-ai/
1•psibi•44m ago•0 comments

Show HN: Sift – local hybrid search CLI in a single Rust binary

https://www.alexdk.com/blog/introducing-sift
1•rupurt•46m ago•0 comments

Is Music Just Sound?

https://perthirtysix.com/is-music-just-sound
1•2opt•51m ago•0 comments

Show HN: RACKS! Give your AI agent a Visa card in 60 seconds

https://twitter.com/Rackspay/status/2031217491528020375
1•rakan1•57m ago•0 comments

Slackfmt: Paste Markdown into Slack keeping formatting intact (via Quill Delta)

https://slackfmt.labs.caue.dev
1•cauethenorio•57m ago•1 comments

SEC Holds Roundtable on the "Retailization" of Private/Alternative Investments

https://natlawreview.com/article/sec-holds-roundtable-retailization-privatealternative-investment...
2•petethomas•57m ago•0 comments

This Doc Sees Dead People

https://alum.up.edu.ph/this-doc-sees-dead-people/
1•thunderbong•58m ago•0 comments

Ask HN: Can Sim2Real gap in robotics be closed?

2•glaksmono•58m ago•0 comments

Three distinct ADHD biotypes identified using brain-first, data-driven approach

https://medicalxpress.com/news/2026-03-distinct-adhd-biotypes-brain-driven.html
2•1659447091•1h ago•1 comments