HNHacker News
TopNewBestAskShowJobs

XiaHua

36 karma · joined May 13, 2025

Founder Traceforce (YC S26)
submissionscomments
XiaHua··on Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps
We monitor both the app layer and the MCP servers. We run a hosted version of https://github.com/traceforce/mcp-xray in our backend to constantly pentest MCPs and their supply chains. If you are going to DEF CON or BSides LV, we'll have our demo labs and CFP to talk about open-source MCP testing.
XiaHua··on Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps
It's always a trade-off between serverless and how much customization we want. The Kong plug-in is easy to customize for us.
XiaHua··on Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps
Thank you!
XiaHua··on Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps
Good luck to your startup as well!
XiaHua··on Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps
What do you use to host your public MCP server? We use Kong and they have lots of security plug-ins to choose from. For example https://developer.konghq.com/plugins/bot-detection/
XiaHua··on Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps
I'm curious how your pentesting tool handles the frequent updates in AI app behaviors and MCP APIs without overwhelming false positives?

---> Our pentest tool has a "secret" step called verification. We run a second agent to verify all the findings are "real". We have a built some pretty complex backend harness on top of our open-source mcp-xray to automate testing. If you are at the DEF CON this year, come to our demo labs and we can chat more.

Would be great to hear more about how you maintain coverage on changing AI/MCP combos without constant manual tuning. ---> It's very hard to be honest. We use agents everywhere but manual tuning is still needed.

XiaHua··on Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps
oh and to add on this, MCP gateways work mostly with remote MCPs only. For the stdio ones, we still need local agents to take care of the controls.
XiaHua··on Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps
Thanks for reaching out out. We have one already https://traceforce.trust.cyberbase.ai/
XiaHua··on Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps
Yes you are spot on! On-device agents can only do so much. We integrate with popular gateways such as Kong to bring MCP controls. We primarily manage the registries for MCPs with vulnerabilities that gateway companies don't do today.
XiaHua··on Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps
That's a great example. It's exactly the kind of behavior we think deserves more attention. It's not a traditional vulnerability but it can significantly influence an agent's decision-making.

Today, mcp-xray (https://github.com/traceforce/mcp-xray) can be used to dynamically (not just statically) test against your MCPs. It can detect security vulnerabilities such as code execution, SSRF, path traversal, authorization bypass, input injection, DoS etc. You can find us at demo labs during DEF CON this year. That said, we think behavioral influence is an important problem and it's an area we're interested in exploring next.

XiaHua··on Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps
I will definitely checkout Runlayer Watch in depth. It seems that it works with coding agents but not web-based agents yet. We've had customers comparing the two solutions. They liked the depth of discovery and the open-source security scanning capabilities.

And I know Harold well at Bluerock. I totally agree that the market is crowded and will only get more crowded which is a good sign that the problem is real.

And yes I totally agree with you that differentiation is the key. I can't say that we have figured this out 100% but our approach is always community first, open-source first. I hope that is the right direction in the long run.

XiaHua··on Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps
Runlayer can be a fit once you know what you want to put behind an MCP gateway.

The challenge we hear from customers is that they don't know what AI apps, MCPs, or tools their employees are actually using. And new things just keep popping up everyday. Without that visibility, it's difficult to know where to apply controls.

XiaHua··on Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps
Thanks for the feedback!

I agree that DROP TABLE executes remotely. The key point is that the decision to invoke the tool is made by coding agents like Claude Code. Traceforce captures those tool calls at the application layer before they're executed.

The gap we focus on is application-level visibility inside AI apps—understanding which MCPs, skills, and tools are connected and what they're doing. A big part of our work has been building an MCP registry so we can accurately identify and classify MCPs, something traditional EDR telemetry doesn't provide.

That said, if your existing EDR already gives you that level of visibility and enforcement, I’d be interested in learning about which EDR you’re using and how it handles MCP and tool-level activity.

XiaHua··on Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps
We are also curious to ask what existing tools are folks using to gain visibility into what's running out there?