frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Cordon – Security gateway for MCP tool calls with HITL approvals

https://github.com/marras0914/cordon
2•babas03•1h ago
MCP lets LLMs call real tools, databases, file systems, APIs. The spec has no security model. An agent is either off or full admin, and "trust the model" is the current answer.

Cordon is an open source MCP gateway. It's a transparent proxy that sits between your LLM client and your MCP servers. Every tool call flows through it. You define policies per tool: allow, block, approve, read only, log only.

The piece I haven't seen elsewhere is synchronous human-in-the-loop approvals. When a tool call hits an "approve" policy, the agent pauses and I get a terminal prompt (or a Slack Block Kit message) with the exact args. I approve or deny. The agent resumes. Every decision is logged.

Install: `npx cordon-cli init` auto-patches your Claude Desktop config in about two minutes. Works with Claude Desktop, Claude Code, Cursor, Windsurf, and any stdio MCP client.

Open source, MIT. Published to the official MCP registry as io.github.marras0914/cordon. There's also a hosted dashboard for centralized audit logs, but the gateway runs local and the CLI is fully offline.

Happy to answer questions about the threat model, why I built it as a proxy vs. a client-side wrapper, or how write-detection works without me enumerating every dangerous tool name.

GitHub: https://github.com/marras0914/cordon Writeup with config examples: https://dev.to/marras0914/mcp-has-no-security-model-heres-ho... Approval flow demo: https://i.imgur.com/nDAVxqN.gif

RecipeScape: An Interactive Tool for Analyzing Cooking Instructions at Scale

https://recipescape.kixlab.org/
1•skadamat•11s ago•0 comments

A Tool I Made

https://github.com/kianacaster/pman
1•kianacaster•1m ago•0 comments

Electrical current might be the key to a better cup of coffee

https://arstechnica.com/science/2026/04/electrical-current-might-be-the-key-to-a-better-cup-of-co...
1•Jimmc414•1m ago•0 comments

Modder releases PS5-Linux that turns console into a functional Linux PC

https://www.notebookcheck.net/Modder-releases-PS5-Linux-that-turns-the-console-into-a-fully-funct...
1•voxadam•2m ago•0 comments

Where Have All the Book Reviews Gone?

https://www.nytimes.com/2026/04/27/books/review/ai-book-reviews.html
1•samclemens•3m ago•0 comments

How to Glue Teflon

https://www.quirkyscience.com/how-to-glue-teflon/
1•BiraIgnacio•7m ago•0 comments

Kuleshov Effect

https://en.wikipedia.org/wiki/Kuleshov_effect
1•hyperific•7m ago•0 comments

Toward a Common Alphabet: There Is No Need for Menedzhment

https://zenodo.org/records/19869374
1•iliatoli•8m ago•0 comments

Structured-Prompt-Driven Development (SPDD)

https://martinfowler.com/articles/structured-prompt-driven/
1•cebert•8m ago•0 comments

Evaluating CUDA Tile for AI Workloads on Hopper and Blackwell GPUs

https://arxiv.org/abs/2604.23466
2•matt_d•12m ago•0 comments

What Is a "Now Page"?

https://nownownow.com/about
2•_vaporwave_•13m ago•1 comments

New study reveals why housing booms and busts are built into the system

https://www.kcl.ac.uk/news/new-study-reveals-why-housing-booms-and-busts-are-built-into-the-system
2•littlexsparkee•13m ago•0 comments

Apple wants to kill your Time Capsule, but they run NetBSD so they can't

https://www.osnews.com/story/144845/apple-wants-to-kill-your-time-capsule-but-they-run-netbsd-so-...
3•latexr•15m ago•1 comments

Blog post about Open Source contribution best practices

https://blog.csystemslab.com/blog/2026-04-26-dont-open-a-pull-request-yet/
2•vhcosta•15m ago•1 comments

Claude system prompt bug wastes user money and bricks managed agents

https://github.com/anthropics/claude-code/issues/49363
2•thomashobohm•20m ago•1 comments

Is it incel to want to be a father? [video][30min]

https://www.youtube.com/watch?v=Pf15HmxooMc
2•Bender•20m ago•0 comments

AI Worries Have Returned to Wall Street. Now Come Earnings

https://www.wsj.com/tech/ai-worries-have-returned-to-wall-street-now-come-earnings-d680e19c
3•htk•21m ago•0 comments

Mesa: A Versioned Filesystem for Agents

https://www.mesa.dev/blog/introducing-mesa-filesystem-for-agents
2•state•23m ago•0 comments

Compiler Testing – Part 1: Coverage-Guided Fuzzing with Grammars and LLMs

https://nowarp.io/blog/compiler-testing-part-1/
2•matt_d•24m ago•0 comments

ChatGPT serves ads. Here's the full attribution loop

https://www.buchodi.com/how-chatgpt-serves-ads-heres-the-full-attribution-loop/
26•lmbbuchodi•25m ago•4 comments

Show HN: Filedge – parse SEC filings for $0.05 via x402, no keys

https://filedge.io/
2•arvindravi•27m ago•0 comments

AI researchers want AI to fake "thinking" – by Mike Elgan

https://www.machinesociety.ai/p/ai-researchers-want-ai-to-fake-thinking-247
3•MaysonL•27m ago•1 comments

Claude for Creative Work

https://www.anthropic.com/news/claude-for-creative-work
4•elsewhen•33m ago•0 comments

GameNova – Turn text prompts into playable 3D games in 60 seconds

https://www.gamenova.io
2•Taskclan•34m ago•0 comments

Show HN: Niimbot Label Printer desktop app with Pretix integration

https://github.com/ooguz/niimbot-printer
2•m3rcury•35m ago•0 comments

Apple Colour Matching Functions Article by LTTLabs

https://www.lttlabs.com/articles/2026/04/11/apple-studio-display-xdr-display-testing-results
2•HeyMeco•36m ago•0 comments

A Milestone in Formalization: The Sphere Packing Problem in Dimension 8

https://www.alphaxiv.org/abs/2604.23468
2•measurablefunc•37m ago•0 comments

Proxies, Sandboxes and Agent Security

https://www.gouthamve.dev/proxies-sandboxes-and-agent-security/
4•gouthamve•38m ago•0 comments

My Login Shell in Assembly

https://isene.org/2026/04/Bare.html
3•birdculture•39m ago•0 comments

VibeBench: Measuring 1k Engineers' Opinions of New Models

https://vibebench.standardagents.ai/
6•jpschroeder•43m ago•2 comments