OSS
Today's Show HN Agent Cluster Skews Defensive — HoneyMCP Ships Decoy 'Ghost Tools' to Catch Attackers Inside MCP Servers
Beyond mcptoon, this morning's Show HN batch is small and mostly security-flavored: barvhaim/HoneyMCP adds a deception layer to MCP servers using decoy 'ghost tools' as honeypots, Sentris scans Supabase projects for missing row-level security and leaked credentials, g-33-L/anansi offers an open-source memory API for LLM apps, and lgxz/dora is a minimal LLM agent with a single bash tool. All four sit at 1–2 points with essentially no discussion. HoneyMCP is the conceptually interesting one — it assumes MCP servers are now a target surface worth instrumenting, which is a notable shift from treating them as plumbing.
Source
↳ Follow the thread