frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Secure SDLC Agents for Claude and Cursor (MCP)

https://github.com/Kaademos/secure-sdlc-agents
1•kirumachi•2h ago
Hey HN,

I have been using Claude Code and Cursor lately and as we all know, they write code incredibly fast but a few times i have noticed they can introduce the same security flaws. For example, you ask the LLM to build a file upload feature, you will get working code in minutes, but it would almost always miss magic-byte validation or leaves you vulnerable to SVG XSS. The LLM optimizes for code that compiles not code that is secure.

To fix this for my own workflow, I made a set of 8 security-focused AI agents (AppSec, GRC, Cloud/Platform, etc) that you can drop into any MCP-compatible tool (Cursor, Windsurf) or use with Claude Code.

To clarify, the goal here is not to say that LLM/AI replaces AppSec or the Secure Software Development Cycle, instead the goal is to provide a series of structured prompts and concrete security artifacts (like STRIDE based threat models and ASVS mapped functional requirements) for developers who are already using AI to write code. The aim is to force the LLM to pause and sort of put on a security hat during specific phases of the SDLC.

What It Actually Is

It is an MIT licenced repo containing the agent prompts, document templates and an MCP server. You can install via Claude marketplace or globally via npm, which gives you a CLI to scaffold git hooks, CodeQL CI Gates and the MCP config. Also included are 3 full walkthroughs in the repo showing how the agents catch things.

I am an Application Security Engineer, and I am really curious to get feedback and critique. Please try it out without any signups using the URL. I will be around to answer any questions

Brutalist Concrete Laptop Stand

https://sam-burns.com/posts/concrete-laptop-stand/
1•sam-bee•10s ago•0 comments

Prepping for the Endgame of the Open Web

https://thehistoryoftheweb.com/prepping-for-the-endgame/
1•speckx•13s ago•0 comments

Machine Learning Library from the 2000s

http://torch.ch/torch3/
1•shrikaranhanda•2m ago•0 comments

Show HN: TexoCAD – Lovable for Hardware

https://www.texocad.ai/
1•torayeff•2m ago•0 comments

FREDCode – Claude-Native Macro Fred Research

https://modolap.com/publication/fred-1
1•ronfriedhaber•3m ago•0 comments

Charcuterie: A Visual Explorer for Unicode

https://charcuterie.elastiq.ch/
1•coinfused•4m ago•0 comments

"Alignment" and "Safety", Part One: What Is "AI Safety"?

https://www.lesswrong.com/posts/siJEByu67fLsgKsQt/alignment-and-safety-part-one-what-is-ai-safety
1•joozio•5m ago•0 comments

Watch this video of how a job interviewer exposes a North Korean fake IT worker

https://techcrunch.com/2026/04/06/watch-this-video-of-how-a-job-interviewer-exposes-a-north-korea...
1•byschii•7m ago•0 comments

Build Native iOS Apps Without a Mac or Code

https://www.scaleify.dev
1•bajero•9m ago•1 comments

‎PocketPal AI App. Run Gemma 4 and other hugging faces models on device

https://apps.apple.com/us/app/pocketpal-ai/id6502579498
1•janandonly•9m ago•0 comments

Show HN: Onboardly – Ask questions about any GitHub codebase in plain English

https://onboardly-ruddy.vercel.app
1•KevStatic•10m ago•0 comments

China to help Cuba with solar energy amid US oil blockade

https://www.scmp.com/economy/china-economy/article/3346978/china-help-cuba-solar-energy-amid-us-o...
1•KnuthIsGod•10m ago•0 comments

Carroll (Crater)

https://en.wikipedia.org/wiki/Carroll_(crater)
1•incognito124•15m ago•0 comments

Emojigo JavaScript

https://github.com/EmojiGO/emojigo-js
2•spotlayn•16m ago•0 comments

The Hacker News Tarpit

https://www.joanwestenberg.com/the-hacker-news-tarpit/
1•latexr•17m ago•0 comments

TinyProgrammer: Self-contained device that writes and runs small Python programs

https://github.com/cuneytozseker/TinyProgrammer
1•thunderbong•19m ago•0 comments

Google's Gemini wrote a 5k-word paper about my empty website

https://phantomauthority.ai
2•Deforth•19m ago•0 comments

Speed Run to Legacy: How Cheap AI Tokens Hide Expensive Mistakes

https://bitbrawn.com/posts/ai-speed-run-to-legacy
1•retrac98•19m ago•0 comments

Health benefits of Paris climate goals could save lives by 2040

https://www.carbonbrief.org/guest-post-health-benefits-of-paris-climate-goals-could-save-millions...
3•lentoutcry•21m ago•0 comments

How Complex is my Code?

https://philodev.one/posts/2026-04-code-complexity/
2•speckx•22m ago•0 comments

Running AI agents safely in a microVM using Docker sandbox

https://andrewlock.net/running-ai-agents-safely-in-a-microvm-using-docker-sandbox/
1•ingve•25m ago•0 comments

Plane trees getting on your nose? The truth about hay fever (2012)

https://theconversation.com/plane-trees-getting-on-your-nose-the-truth-about-hay-fever-9223
2•zeristor•27m ago•0 comments

AI Won't Replace You, but a Manager Using AI Will

https://yanivpreiss.com/2026/04/06/ai-wont-replace-you-but-a-manager-using-ai-will/
6•PretzelFisch•30m ago•1 comments

The Artemis II astronauts have flown around the moon

https://www.newscientist.com/article/2522113-the-artemis-ii-astronauts-have-flown-around-the-moon/
1•jonbaer•30m ago•0 comments

Cheap Code means more Governance

https://fffej.substack.com/p/cheap-code-means-more-governance
2•PretzelFisch•30m ago•0 comments

Yoopla – 400 free online tools with no sign-up

https://www.yoopla.net/en
1•yoopla_dev•30m ago•2 comments

Germany Power Prices Turn Deeply Negative on Renewables Surge

https://www.bloomberg.com/news/articles/2026-04-07/germany-power-prices-turn-deeply-negative-on-r...
16•rustoo•34m ago•2 comments

Minimum Connection Times at Airports Worldwide

https://minimumconnectiontime.com/
2•beatthatflight•35m ago•0 comments

Show HN: HumansMap, Graph visualization of 3M+ Wikidata persons

https://humansmap.com
2•abstracthinker•35m ago•1 comments

Tech companies are cutting jobs and betting on AI. The payoff is not guaranteed

https://www.theguardian.com/technology/2026/apr/06/tech-layoffs-ai-work
3•victortalkstech•37m ago•0 comments