Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
coderinsan
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
OpenAI's rogue agents used ntfy.sh as a pub/sub channel
3 points
by
coderinsan
13d ago
|
0 comments
2.
▲
Lethal Trifecta – Using Notion AI's Web Search Tool to Leak Private Notion Pages
(codeintegrity.ai)
2 points
by
coderinsan
1y ago
|
2 comments
3.
▲
by
coderinsan
1y ago
Hey HN — yesterday Notion released AI agent support on their platform with support for MCP servers and custom AI agents. It didn’t take us long to find an example of a lethal trifecta attack in which, through indirect prompt injection, we w
4.
▲
by
coderinsan
1y ago
How does this protect against lethal trifecta attacks like the ones here - tramlines.io/blog ?
5.
▲
by
coderinsan
1y ago
How are you protecting against Willison's lethal trifecta attacks in agents connected to tools like shown here - https://tramlines.io/blog
6.
▲
Official MCPS are at risk to Willison's lethal trifecta attack
(tramlines.io)
2 points
by
coderinsan
1y ago
|
1 comments
7.
▲
by
coderinsan
1y ago
Hey HN we’ve been collecting lethal trifecta based attack scenarios on official MCPs and implementing guardrails against them for a while now. It's incredible to see how many of the official MCPs are susceptible to these attacks. With
8.
▲
Examples of lethal trifecta based MCP exploits
(tramlines.io)
2 points
by
coderinsan
1y ago
|
2 comments
9.
▲
by
coderinsan
1y ago
Hey HN we’ve been collecting lethal trifecta based attack scenarios on official MCPs and implementing guardrails against them for a while now. It's incredible to see how many of the official MCPs are susceptible to these attacks. With
10.
▲
by
coderinsan
1y ago
“We’ve found numerous MCP exploits from the official MCPs in our blog ( https://tramlines.io/blog ) and have been powering runtime guardrails to defend against lethal trifecta MCP attacks for a while now ( https://t
11.
▲
by
coderinsan
1y ago
A similar one we found at tramlines.io where AI email clients can get prompt injected - https://www.tramlines.io/blog/why-shortwave-ai-email-with-mc...
12.
▲
The insanity of integrating AI into email clients
(tramlines.io)
3 points
by
coderinsan
1y ago
|
0 comments
13.
▲
by
coderinsan
1y ago
This is precisely why we tell people not to run MCPs without guardrails - tramlines.io
14.
▲
Claude added working API keys in Cline
(old.reddit.com)
2 points
by
coderinsan
1y ago
|
0 comments
15.
▲
Exercise caution when agentic e-shopping
(tramlines.io)
1 points
by
coderinsan
1y ago
|
0 comments
16.
▲
Malicious MCP code execution through Shortwave AI Email
(tramlines.io)
2 points
by
coderinsan
1y ago
|
0 comments
17.
▲
Weaponizing Shopify MCP for Highly Persuasive Selling
(tramlines.io)
1 points
by
coderinsan
1y ago
|
0 comments
18.
▲
Shopify MCP Can Be Abused to Manipulate Customer Purchases
(tramlines.io)
3 points
by
coderinsan
1y ago
|
0 comments
19.
▲
Pythonic Guardrails for MCP Servers
(github.com)
2 points
by
coderinsan
1y ago
|
0 comments
20.
▲
Official Azure MCP exploited to steal users Keyvaults secrets
(tramlines.io)
4 points
by
coderinsan
1y ago
|
1 comments
21.
▲
by
coderinsan
1y ago
Here's another one we found related to the lethal trifecata problem in AI Email clients like Shortwave that have integrated MCPs - https://www.tramlines.io/blog/why-shortwave-ai-email-with-mc...
22.
▲
by
coderinsan
1y ago
From tramlines.io here - We found a similar exploit in the official Neon DB MCP - https://www.tramlines.io/blog/neon-official-remote-mcp-explo...
23.
▲
by
coderinsan
1y ago
From tramlines.io here - We found a similar exploit in the official Neon DB MCP - https://www.tramlines.io/blog/neon-official-remote-mcp-explo...
24.
▲
Why Shortwave AI Email with MCP integration Is a Phisher’s White Whale
(tramlines.io)
2 points
by
coderinsan
1y ago
|
0 comments
25.
▲
A Phisher's White Whale: Shortwave AI Email with MCP Integration
(tramlines.io)
2 points
by
coderinsan
1y ago
|
1 comments
26.
▲
by
coderinsan
1y ago
We power Tramlines.io, a platform that offers runtime guardrails to secure MCP interactions. Tools like Shortwave AI Email, when combined with MCP, open up rich capabilities—but also new attack surfaces. Tramlines acts as a protective layer
27.
▲
Neon DB MCP exploited to exfiltrate customer data
(tramlines.io)
3 points
by
coderinsan
1y ago
|
1 comments
28.
▲
Securing GitHub Copilot agent mode and MCP Workflows with runtime guardrails
(tramlines.io)
3 points
by
coderinsan
1y ago
|
0 comments
29.
▲
Runtime guardrails to prevent annoying token bleeding with Playwright MCP
(tramlines.io)
1 points
by
coderinsan
1y ago
|
1 comments
30.
▲
by
coderinsan
1y ago
We wrote a blogpost on the runtime guardrails tramlines.io powers to stop token bleeding that is common with browser automation MCPs like Playwright etc. These guardrails should allow for smoother usage of Playwright with automation workflo
More ›