frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

We scanned 73 open-source MCP servers. Here's what source code analysis found

1•sigildev•1h ago
We ran Sigil, our open-source security scanner, against 73 of the most-installed MCP servers on Smithery. Every finding was manually verified against the source code.

Results: 66 passed (90%). 5 had configuration warnings. 2 failed with real security-relevant patterns in their tool handlers.

The two failures are instructive:

telegram-mcp scored F with 12 findings. Its send_photo, send_video, and send_document tools accept a file_path parameter with zero path validation and no directory allowlist. An LLM could call send_photo(chat, "/etc/passwd") and the server would attempt to send it. It also runs HTTP endpoints with verbose error output.

mcp-sqlite-server scored F with 9 findings. It passes user-provided SQL to conn.execute() with a startswith("select") guard. Python's sqlite3 blocks multi-statement execution, so DROP TABLE isn't possible — but single-statement bypasses work: UNION-based schema extraction, pragma metadata access, and potentially load_extension(). A guard that looks restrictive but isn't creates false confidence. It also runs SSE on 0.0.0.0:8000 over plain HTTP with debug logging enabled.

Both are community-maintained projects doing useful things. But the patterns they contain — unrestricted file access, raw SQL execution with insufficient guards — are exactly the kind of thing that should get caught before deployment.

Sigil reads MCP server source code (TypeScript and Python), finds tool handler registrations, and detects dangerous patterns with 16 rules. It does pattern analysis with tool-handler scoping — it only flags code within actual MCP tool contexts, not build scripts or utilities.

We notified both maintainers before publishing.

npx @sigildev/sigil .

MIT licensed. No account. GitHub: https://github.com/sigildev/sigil

Homo Sapiens vs. the Designer – Class Action Complaint

https://content.riif.com/class-action/
1•philiptranp•2m ago•0 comments

The Price Discovery Problem in the AI Debate

https://davefriedman.substack.com/p/the-price-discovery-problem-in-the
1•walterbell•2m ago•0 comments

Coordination patterns for multi-model AI systems

https://datda.substack.com/p/towards-reliable-agentic-systems
1•rapatel0•3m ago•1 comments

Gcannon – C io_uring HTTP/1.1 and WebSocket load generator for Linux

https://github.com/MDA2AV/gcannon
1•MDA2AV•3m ago•0 comments

HN: I simulated a real cancer case and predicted why some tumors didn't respond

https://github.com/ResakaGit/RESONANCE
1•agumza1•6m ago•0 comments

AgentDesk MCP: Adversarial review for LLM agent outputs (open source)

https://github.com/Rih0z/agentdesk-mcp
1•ezark_dev•8m ago•0 comments

Small Engines

https://scottlocklin.wordpress.com/2026/03/25/very-small-engines/
1•o_nate•8m ago•0 comments

Adult Swim Bumpers Collection

https://www.bumpworthy.com/bumps/classic/
1•marysminefnuf•9m ago•0 comments

Ask HN: Hypothetical Question or Thought Exercise

1•Bender•11m ago•0 comments

The Anti-Intellectualism of Silicon Valley Elites

https://www.elizabethspiers.com/the-anti-intellectualism-of-silicon-valley-elites/
3•speckx•12m ago•0 comments

AI, Human Cognition and Knowledge Collapse

https://www.nber.org/papers/w34910
1•kawera•13m ago•0 comments

Solar-powered truck charging gains ground on South Africa's freight corridors

https://apnews.com/article/charge-ev-trucks-solar-energy-africa-e153cf76cec084b1a6c681386840b977
2•PaulHoule•13m ago•0 comments

Apple at 50 – Apple Vision Pro body tracking, a disabled engineer, UK Lawsuit

https://edgecaseexistence.com/articles/apple-50/
1•iheartbiggpus•13m ago•0 comments

America's Best New Weapon in Iran Is a Drone Inspired by Iran

https://www.wsj.com/politics/national-security/iran-war-shahed-drone-65d0aced
1•uxhacker•15m ago•1 comments

Shared Moments – Wedding Album Created by your guests for you

https://www.shared-moments.com/
3•miaholloway•15m ago•1 comments

Tamp.dev – save up to 63% on AI tokens (free, works with Claude Code)

https://tamp.dev
1•kulesh•15m ago•0 comments

Build a CLI for AI agents and humans in less than 10 mins

https://twitter.com/GoogleCloudTech/status/2038778093104779537
1•rmason•19m ago•0 comments

The Launch of COBOL Weekly

https://cobolweekly.com/
1•rmason•20m ago•0 comments

Architectural Decision Records

https://adr.github.io/
3•ahamez•21m ago•0 comments

Apple at 50: Own the Whole Stack

https://blog.dreamfold.dev/post/apple-at-50/
1•darryl-c•22m ago•0 comments

The Sci-Fi Novelist Who Disappeared for Decades

https://www.newyorker.com/books/under-review/the-sci-fi-novelist-who-disappeared-for-decades
1•petethomas•22m ago•0 comments

Opus 4.6 vs. GPT 5.4 – an opinionated take for my diary

https://doruk.ch/blog/claude-opus-4-6-vs-gpt-5-4
1•peaktwilight•22m ago•0 comments

Linear Types Proposal for Hare

https://yerinalexey.srht.site/borrow/notes.html
1•birdculture•23m ago•0 comments

Iceberg, the Right Idea – The Wrong Spec – Part 1 of 2: History

https://www.database-doctor.com/posts/iceberg-is-wrong-1
2•b-man•25m ago•0 comments

A 5x faster Maestro runner implemented in Go

https://github.com/devicelab-dev/maestro-runner
1•__cayenne__•25m ago•0 comments

Nuclear Batteries Could Change Everything, and China Is Ahead

https://www.bgr.com/2132390/china-nuclear-batteries/
1•thunderbong•27m ago•1 comments

Inside the Claude Code source

https://gist.github.com/Haseeb-Qureshi/d0dc36844c19d26303ce09b42e7188c1
1•gaws•29m ago•0 comments

The Algorithm: Idiom of Modern Science (2006)

https://www.cs.princeton.edu/~chazelle/pubs/algorithm.html
1•kerim-ca•29m ago•0 comments

OnlyOffice just pulled its 8-year partnership with Nextcloud

https://www.xda-developers.com/onlyoffice-pulled-its-8-year-partnership-with-nextcloud-licensing-...
3•TechTechTech•29m ago•0 comments

YC-backed AI startup can now prescribe psychiatric drugs, first in world

https://nypost.com/2026/03/27/business/artificial-intelligence-can-now-prescribe-mental-health-dr...
1•sizzle•31m ago•0 comments