Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
XiaHua
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
XiaHua
2mo ago
We monitor both the app layer and the MCP servers. We run a hosted version of https://github.com/traceforce/mcp-xray in our backend to constantly pentest MCPs and their supply chains. If you are going to DEF CON or BSi
2.
▲
by
XiaHua
2mo ago
It's always a trade-off between serverless and how much customization we want. The Kong plug-in is easy to customize for us.
3.
▲
by
XiaHua
2mo ago
Thank you!
4.
▲
by
XiaHua
2mo ago
Good luck to your startup as well!
5.
▲
by
XiaHua
2mo ago
What do you use to host your public MCP server? We use Kong and they have lots of security plug-ins to choose from. For example https://developer.konghq.com/plugins/bot-detection/
6.
▲
by
XiaHua
2mo ago
I'm curious how your pentesting tool handles the frequent updates in AI app behaviors and MCP APIs without overwhelming false positives? ---> Our pentest tool has a "secret" step called verification. We run a second agent
7.
▲
by
XiaHua
2mo ago
oh and to add on this, MCP gateways work mostly with remote MCPs only. For the stdio ones, we still need local agents to take care of the controls.
8.
▲
by
XiaHua
2mo ago
Thanks for reaching out out. We have one already https://traceforce.trust.cyberbase.ai/
9.
▲
by
XiaHua
2mo ago
Yes you are spot on! On-device agents can only do so much. We integrate with popular gateways such as Kong to bring MCP controls. We primarily manage the registries for MCPs with vulnerabilities that gateway companies don't do today.
10.
▲
by
XiaHua
2mo ago
That's a great example. It's exactly the kind of behavior we think deserves more attention. It's not a traditional vulnerability but it can significantly influence an agent's decision-making. Today, mcp-xray ( https:
11.
▲
by
XiaHua
2mo ago
I will definitely checkout Runlayer Watch in depth. It seems that it works with coding agents but not web-based agents yet. We've had customers comparing the two solutions. They liked the depth of discovery and the open-source security
12.
▲
by
XiaHua
2mo ago
Runlayer can be a fit once you know what you want to put behind an MCP gateway. The challenge we hear from customers is that they don't know what AI apps, MCPs, or tools their employees are actually using. And new things just keep popp
13.
▲
by
XiaHua
2mo ago
Thanks for the feedback! I agree that DROP TABLE executes remotely. The key point is that the decision to invoke the tool is made by coding agents like Claude Code. Traceforce captures those tool calls at the application layer before they&#
14.
▲
by
XiaHua
2mo ago
We are also curious to ask what existing tools are folks using to gain visibility into what's running out there?
15.
▲
Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps
44 points
by
XiaHua
2mo ago
|
28 comments