Hacker Newsnew | past | comments | ask | show | jobs | submit | joshwarwick15's commentslogin


This can be easily used to search for seeds/private keys when AI coding agents are in YOLO mode.


The "lethal trifecta" refers to default configurations, excessive permissions, and inadequate authentication - three factors that plague MCP implementations just as they did with earlier technologies.



These exploits are all the same flavour - untrusted input, secrets and tool calling. MCP accelerates the impact by adding more tools, yes, but it’s by far not the root cause - it’s just the best clickbait focus.

What’s more interesting is who can mitigate - the model provider? The application developer? Both? OpenAI have been thinking about this with the chain of command [1]. Given that all major LLM clients’ system prompts get leaked, the ‘chain of command’ is exploitable to those that try hard enough.

[1] https://model-spec.openai.com/2025-02-12.html#ignore_untrust...



List of servers to connect to here: https://github.com/jaw9c/awesome-remote-mcp-servers


That's great! It would be even better if one of the features included in the table was whether given MCP supports OAuth Dynamic Client Registration, which optional in the MCP standard.


The MCP server technically doesn't support DCR. The authorization server for the MCP server does, which is a minor distinction.

Have you seen significant need for this? I've been trying to find data on things like "how many MCP clients are there really" - if it takes off where everything is going to be an MCP client && dynamically discovering what tools it needs beyond what it was originally set up for, sure.


Thanks!!!


Use the code FOUNDINGBETA to get 10mins airtime free :)


Finally added support for Oauth based remote MCP severs! List of site to connect to here: https://github.com/jaw9c/awesome-remote-mcp-servers


List of remote MCP servers to use here: https://github.com/jaw9c/awesome-remote-mcp-servers


Looks like it’ll pretty restrictive and not allow tool updates dynamically - not great for remote MCP servers



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: