frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Show HN: cMCP, deny an AI agent's tool call and get a signed receipt

https://github.com/agentrust-io/cmcp
8•mosiddi•1h ago

Comments

mosiddi•1h ago
Author here. cMCP sits between an agent and its MCP tool servers. Every tool call is evaluated against a Cedar policy before it is forwarded, and the gateway emits a signed, hash-chained record of what it decided. MIT, Python 3.11+.

Ten-minute laptop version, no hardware and no signup: https://agentrust-io.com/quickstart/ You install the runtime, write one forbid rule, watch a tool call come back 403 POLICY_DENY before a byte leaves the machine, then verify the receipt it produced.

That last step is the only part I would care about if a stranger posted this, so: run the verifier on a laptop and you get six checks passing and one failing.

  [cmcp verify] hardware_attestation     FAIL  software-only mode
  [cmcp verify] RESULT: FAIL (partially_verified)
Exit code 1. Software mode has no hardware root of trust to offer, so the tool refuses to call the result verified. I would rather hand you that than a green check that means nothing. It reports verified only when the platform evidence is itself cryptographically checked: for SEV-SNP the report signature plus VCEK to ASK to ARK with the ARK pinned by the operator, for TDX the DCAP quote to a pinned Intel root, for TPM 2.0 the signature over the TPMS_ATTEST plus the AK certificate chain to a manufacturer CA the operator pins.

We got that last one wrong, and it is still wrong in the release you would install right now. The tpm2 branch checked the measurement and never the signature over it, so a forged TPMS_ATTEST with correct magic and matching qualifying_data was reported as hardware-attested. That is issue #370, fixed in #469, on main as of this week and not yet on PyPI, so pip install gives you 0.3.0 and 0.3.0 has the defect. It ships as 0.4.0 rather than a patch because the fix moves signed evidence to a new field that older verifiers reject. Nothing in the laptop quickstart touches that path, but if you are evaluating the TPM verifier specifically, install from main. LIMITATIONS.md is where we keep the rest of these, including the ones still open.

Two boundaries worth naming before anyone has to ask. It governs the tool boundary, not the model boundary: it sees no inference, no context window, and no chat output that never becomes a tool call. And as someone who sells confidential computing for a living, current CC silicon is not custody-grade against an attacker who physically owns the machine, see TEE.fail and BadRAM. The threat model this actually buys you is the rogue admin and the compromised host OS at an operator you have some basis to trust, not a hostile hardware owner.

Happy to go into the Cedar evaluation path, the audit chain format, or why the receipt is a separate spec rather than a log line.

recursive•1h ago
To the OP: your sibling explanation comment here is flagged and dead. I don't know why.

Show HN: Simple algorithm and color space to generate diverse skin tones

https://toneyalexander.github.io/inclusive-color-space/
324•automatoney•4h ago•71 comments

Show HN: Fine-tune an 8B model on a 4 GB laptop GPU

https://github.com/MakazhanAlpamys/Soup
107•MakazhanAlpamys•8h ago•20 comments

Show HN: TormentNexus – Local-first Go control plane with persistent memory

https://tormentnexus.site
2•TormentNexusAI•45m ago•0 comments

Show HN: SIEMatic, a fair-sourced observability and security platform

https://github.com/mcindi/siematic
6•ilovetux•3h ago•3 comments

Show HN: Jido Assembly; Slack Clone in Pure Elixir with Integrated Agents

https://jido.run/blog/jido-assembly-slack-clone
8•mikehostetler•4h ago•0 comments

Show HN: Pure front end only image tools – Trustedimagetools

https://trustedimagetools.com/
2•subhash_k•1h ago•1 comments

Show HN: Hackercast – Listen to Hacker News stories as a podcast

https://hackercast.app
2•Noyis•2h ago•0 comments

Show HN: Run an 80B Qwen in 4.3 GB of RAM on a Mac, and a 35B on an iPhone

https://github.com/leonickson1/Swiftlet
294•leonickson•1d ago•131 comments

Show HN: OpenEdit – Your coding agent can now edit videos

https://github.com/veedstudio/open-edit
6•sabbakeynejad•5h ago•2 comments

Show HN: Simple self-hosted LLM assistant with user-steered compounding context

https://github.com/kol3x/pawmc
4•kol3x•5h ago•0 comments

Show HN: Terminal stock dashboard in Rust with SEC Form 4 insider trades

https://github.com/makeev/alphai-tui
3•mmakeev•2h ago•0 comments

Show HN: VerusCite, a tool to check for hallucinations in academic articles

https://veruscite-data.com/
2•apwheele•2h ago•0 comments

Show HN: Adapt, Automatically Turns Files into REST APIs, Web UI, and MCP

https://github.com/mcindi/adapt
5•ilovetux•4h ago•0 comments

Show HN: Korvo – Local-first AI workspace that traces answers to the source

https://www.korvo.xyz/
4•akshay_bhardwaj•4h ago•0 comments

Show HN: I built a Buffer alternative that also generates the videos

https://videoai.me/login
2•Paul_Grsl•2h ago•0 comments

Show HN: Gantt resource planning vs. event scheduling in RevoGrid

https://benchmark.rv-grid.com/revogrid-vs-bryntum-scheduling/
2•kumakint•3h ago•0 comments

Show HN: Give your agents a personal internet based on what you've surfed

https://github.com/Fergana-Labs/stash/blob/main/docs/ai-native-bookmarks.md
2•samzliu•3h ago•0 comments

Show HN: I got tired of sharing files between devices, so I built TapSend

https://tapsend.app
2•TapSend•3h ago•0 comments

Show HN: OldHand A Claude/Codex plugin to verify the development flow end-to-end

https://github.com/berwinsingh/oldhand
2•berwinsingh•3h ago•0 comments

Show HN: Blender for AI Agents

https://www.mixar.app
6•namanbhargava18•3h ago•4 comments

Show HN: I Repurposed Unit Tests to Show How Much Coding Agents "Improvise"

https://github.com/RudderCode/Rudder
2•vivekyyy•3h ago•0 comments

Show HN: FastStrapy – A create-next-app-inspired CLI for FastAPI

https://github.com/AnoopGeorge418/faststrapy
2•anoopgeorge418•3h ago•0 comments

Show HN: I redesigned my self-hosted data manager's UI (4k stars, v2

https://github.com/Volmarg/personal-management-system
2•volmarg_reiso•4h ago•0 comments

Show HN: Bean Network Tester – open-source bad network simulator

https://github.com/donislawdev/BeanNetworkTester
2•donislawdev•4h ago•0 comments

Show HN: BubbleHub - a local runtime and hosting for LLM agents

https://github.com/bublhub/BubbleHub
2•danielsbubblee•4h ago•0 comments

Show HN: Clai – AI for the command line (stdin → LLM → stdout)

https://github.com/maxrodrigo/clai
3•maxrodrigo•4h ago•0 comments

Show HN: Moorage – a better way to mount and view MTP devices in macOS

https://github.com/skuthus/Moorage
3•widowlark•4h ago•0 comments

Show HN: mcpvessel run untrusted MCP servers caged, egress denied by default

https://github.com/okedeji/mcpvessel
4•Toby11•4h ago•0 comments

Show HN: Clayrune – Run Claude Code agents in parallel without losing context

https://github.com/ronle/clayrune
2•Clayrune•4h ago•0 comments

Show HN: XTokenChecker – Verifies model identities of your AI gateway

https://xtokenchecker.com/
2•zizheruan•4h ago•0 comments