Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If your application can be significantly diverted from its intended purpose by the presence of instructions in a normal input file, your application is unsuitable for production workloads.

This feels like installing an "antivirus" addon into wordpress instead of updating php.



I had the same thought while building this, but I really feel a tool like this is needed as MCP has a lot of surface area for attacks. Any MCP server that gets hacked exposes all users of that MCP server to serious security risk, unless they are really careful about inspecting every single MCP tool call they make.


MCP does have a lot of surface area for attacks, but I feel like that needs to be addressed from within MCP implementations.


You've just described human users. I see no new flaws




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: