<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: mavzer</title><link>https://news.ycombinator.com/user?id=mavzer</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 25 Jul 2026 03:17:08 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=mavzer" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by mavzer in "The State of MCP Security [pdf]"]]></title><description><![CDATA[
<p>100%!! All AI tooling (MCPs, skills, models etc) has to go through the same scrutiny applied to any other web service. But as always, security is an afterthought that comes back to bite.</p>
]]></description><pubDate>Mon, 13 Jul 2026 08:51:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=48889703</link><dc:creator>mavzer</dc:creator><comments>https://news.ycombinator.com/item?id=48889703</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48889703</guid></item><item><title><![CDATA[New comment by mavzer in "The State of MCP Security [pdf]"]]></title><description><![CDATA[
<p>Nice. Basically, I see 3 ways the MCP ecosystem converging<p>- Centralized, well trusted sources for MCP servers
- Technical people like you creating their own, private MCPs for specific use cases
- An MCP governance layer that brings a bit of sense into this new world<p>Otherwise, it’s a security time bomb. We already see MCP specific attacks out in the wild.</p>
]]></description><pubDate>Sun, 12 Jul 2026 23:15:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48885849</link><dc:creator>mavzer</dc:creator><comments>https://news.ycombinator.com/item?id=48885849</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48885849</guid></item><item><title><![CDATA[New comment by mavzer in "Ask HN: What Are You Working On? (July 2026)"]]></title><description><![CDATA[
<p><a href="https://index.canopii.dev" rel="nofollow">https://index.canopii.dev</a><p>Part of my job is to approve / reject MCP servers based on how secure they are and whether they are suitable for use in an enterprise environment. I was tired of my team being called the bottleneck to AI adoption, so I set out to automate the whole process.<p>I periodically collect the MCP servers and every new version from the Official MCP registry and assign them a score based on 29 distinct criteria like runtime guardrails (e.g. destructive tools, over broad permissions, rug pulls), SAST scans and transport & trust model.<p>As a result of this exercise, I found that 1 in every 10 MCP servers is pretty much unusable (score 40/100 or below). 18% of the popular MCP servers with 1000+ GitHub stars contain one or more security issues. 184 servers to date have changed their tool definitions after publication, which may indicate a "rug pull" attack.<p>I built this for security minded people who also want to be at the forefront of AI adoption and for security teams who are tired to be called the bottleneck.<p>Browsing the index is completely free, you only have to request an API key if you want automated, programmatic lookups for any workflow.<p>Feedback is always welcome!</p>
]]></description><pubDate>Sun, 12 Jul 2026 22:39:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=48885595</link><dc:creator>mavzer</dc:creator><comments>https://news.ycombinator.com/item?id=48885595</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48885595</guid></item><item><title><![CDATA[The State of MCP Security [pdf]]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.canopii.dev/State%20of%20MCP%20Security%202026.pdf">https://www.canopii.dev/State%20of%20MCP%20Security%202026.pdf</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48884647">https://news.ycombinator.com/item?id=48884647</a></p>
<p>Points: 38</p>
<p># Comments: 4</p>
]]></description><pubDate>Sun, 12 Jul 2026 20:49:46 +0000</pubDate><link>https://www.canopii.dev/State%20of%20MCP%20Security%202026.pdf</link><dc:creator>mavzer</dc:creator><comments>https://news.ycombinator.com/item?id=48884647</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48884647</guid></item><item><title><![CDATA[Show HN: A Trust Index for MCP Servers]]></title><description><![CDATA[
<p>As a security professional whose employer has given Claude and various other AI tooling to everyone at the company, I kept finding myself as the bottleneck because my team had to review sometimes 4-5 repositories of MCP servers a day just to give a verdict whether it's safe to use in an enterprise environment.<p>So to make my life easier, I built an easy to read index that pulls all the MCP servers from the Official MCP Registry (<a href="https://registry.modelcontextprotocol.io/" rel="nofollow">https://registry.modelcontextprotocol.io/</a>) periodically and scores them automatically based on several criteria like runtime guardrails, SAST scans, transport model etc.<p>I also recently made it available via an API so that others can integrate it into their workflow.<p>Feedback is always welcome!!!<p>PS: Index came first, it's completely free (you just have to request the API access, no payment required) and it works great (12k MCP servers scanned&scored and still counting!) for my use case so I started thinking whether I can govern the AI adoption a bit more in a friendly way without being the bottleneck. That's when the Canopii platform came to be. This is not meant as an ad for that.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48874692">https://news.ycombinator.com/item?id=48874692</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 11 Jul 2026 18:57:14 +0000</pubDate><link>https://index.canopii.dev</link><dc:creator>mavzer</dc:creator><comments>https://news.ycombinator.com/item?id=48874692</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48874692</guid></item></channel></rss>