HNHacker News
TopNewBestAskShowJobs

coderinsan

72 karma · joined June 22, 2024

submissionscomments
coderinsan··on Lethal Trifecta – Using Notion AI's Web Search Tool to Leak Private Notion Pages
Hey HN — yesterday Notion released AI agent support on their platform with support for MCP servers and custom AI agents. It didn’t take us long to find an example of a lethal trifecta attack in which, through indirect prompt injection, we were able to get Notion AI to leak data via its web search tool.
coderinsan··on Show HN: Pgmcp, an MCP server to query any Postgres database in natural language
How does this protect against lethal trifecta attacks like the ones here - tramlines.io/blog ?
coderinsan··on Launch HN: Rowboat (YC S24) – Open-source IDE for multi-agent systems
How are you protecting against Willison's lethal trifecta attacks in agents connected to tools like shown here - https://tramlines.io/blog
coderinsan··on Official MCPS are at risk to Willison's lethal trifecta attack
Hey HN we’ve been collecting lethal trifecta based attack scenarios on official MCPs and implementing guardrails against them for a while now. It's incredible to see how many of the official MCPs are susceptible to these attacks. With ChatGPT’s integrated MCP support lethal trifecta attacks have become much more relevant.
coderinsan··on Examples of lethal trifecta based MCP exploits
Hey HN we’ve been collecting lethal trifecta based attack scenarios on official MCPs and implementing guardrails against them for a while now. It's incredible to see how many of the official MCPs are susceptible to these attacks. With ChatGPT’s integrated MCP support lethal trifecta attacks have become much more relevant.
coderinsan··on ChatGPT Developer Mode: Full MCP client access
“We’ve found numerous MCP exploits from the official MCPs in our blog (https://tramlines.io/blog) and have been powering runtime guardrails to defend against lethal trifecta MCP attacks for a while now (https://tramlines.io)
coderinsan··on Comet AI browser can get prompt injected from any site, drain your bank account
A similar one we found at tramlines.io where AI email clients can get prompt injected - https://www.tramlines.io/blog/why-shortwave-ai-email-with-mc...
coderinsan··on Replit AI deletes entire database during code freeze, then lies about it
This is precisely why we tell people not to run MCPs without guardrails - tramlines.io
coderinsan··on Supabase MCP can leak your entire SQL database
Here's another one we found related to the lethal trifecata problem in AI Email clients like Shortwave that have integrated MCPs - https://www.tramlines.io/blog/why-shortwave-ai-email-with-mc...
coderinsan··on Supabase MCP can leak your entire SQL database
From tramlines.io here - We found a similar exploit in the official Neon DB MCP - https://www.tramlines.io/blog/neon-official-remote-mcp-explo...
coderinsan··on Supabase MCP can leak your entire SQL database
From tramlines.io here - We found a similar exploit in the official Neon DB MCP - https://www.tramlines.io/blog/neon-official-remote-mcp-explo...
coderinsan··on A Phisher's White Whale: Shortwave AI Email with MCP Integration
We power Tramlines.io, a platform that offers runtime guardrails to secure MCP interactions. Tools like Shortwave AI Email, when combined with MCP, open up rich capabilities—but also new attack surfaces. Tramlines acts as a protective layer to intercept and constrain malicious or unintended MCP tool usage
coderinsan··on Runtime guardrails to prevent annoying token bleeding with Playwright MCP
We wrote a blogpost on the runtime guardrails tramlines.io powers to stop token bleeding that is common with browser automation MCPs like Playwright etc.

These guardrails should allow for smoother usage of Playwright with automation workflows in Claude Code, Cursor etc

coderinsan··on Visualize real world attack chains for any MCP server
Hey everyone, It’s currently very difficult to block control flow and data flow exploit attacks on agentic AI systems. To demonstrate this, we built a dashboard that models specific tool call sequences to replicate real-world exploit scenarios.
coderinsan··on A Knockout Blow for LLMs?
On another note it is ridiculously easy to find attack exploits for any of the popular MCP servers serving traffic. We build a dashboard where you can model exploits yourself - https://hack.mcpwned.com
coderinsan··on Poison everywhere: No output from your MCP server is safe
We wrote a fun tool where we trained an LLM to find end to end control flow, data flow exploits for any open source MCP server - https://hack.mcpwned.com/dashboard/scanner
coderinsan··on Interactive dashboard to visualize attack chain of MCP exploits
Check out the MCPwned scanner—it generates detailed control flow, data flow, and side channel exploits for popular MCP servers.
coderinsan··on Mutmut – Python Mutation Tester
Check out our project Mutahunter - we made use of LLMs to do the mutations at the AST level - https://github.com/codeintegrity-ai/mutahunter
coderinsan··on SIEM Purpose Built for MCP
Our team has been running some interesting exploit scenarios within MCP interactions—mirroring the kinds of events an EDP would typically log on a Mac. This led us to build an EDP for Mac, paired with a purpose-built SIEM designed to analyze MCP logs.

We’re now opening a waitlist for the private beta.

coderinsan··on Ask HN: What are you working on? (April 2025)
Venture backed thing on language agnostic semantic mutation testing- testcode.ai
coderinsan··on [dead]
In today’s rapidly expanding world of AI development tooling, vibe coders—regardless of their software engineering background—are effectively rate-limited for production cases by how quickly and how early in the development cycle they can test their code.

Because the quality of LLM-generated code depends on both prompt quality and a developer’s software experience, writing code faster with LLMs puts more stress on these constraints, often resulting in reduced code quality.

As we move further “to the right” in the dev cycle, the cost and duration of software testing grow exponentially. Vibe code is harder to test, slowing the testing process and ultimately restricting software development speed—undermining the very benefits of vibe coding.

Our goal is to minimally reduce the efficiency gains of vibe coding while fully leveraging trusted shift-left testing approaches.

At https://testcode.ai/products, we are pushing for mutation testing to become the standard companion for vibe coders. Highly targeted semantic mutations optimally challenge the seams of vibe code, giving vibe coders the confidence to keep shipping code while knowing that edge cases are being covered.

coderinsan··on RLHF is just barely RL
This is exactly what we are doing with Mutahunter, AI is exceedingly good at writing edge case tests to test code and will only continue to get better at this. Check out Mutahunter here https://github.com/codeintegrity-ai/mutahunter
coderinsan··on CrowdStrike Update: Windows Bluescreen and Boot Loops
CrowdStrike today has shown why it's absolutely crucial to test code before deployment, say no to YOLO deployments with LLM powered software testing https://github.com/codeintegrity-ai/mutahunter
coderinsan··on Show HN: Mutahunter – LLMs to support mutating testing for all major languages
Hey, we are announcing a Cash Bounty Program to build out some high-priority features for Mutahunter More details here: https://github.com/codeintegrity-ai/mutahunter#cash-bounty-p...