今日已更新 311 条资讯 | 累计 29453 条内容
关于我们

今日精选

HOT

最新资讯

共 29453 篇
第 229/1473 页
AI 资讯 Dev.to

MCPRadar: A Security Scanner Built for the MCP Ecosystem published: true tags: mcp, security, ai, opensource

Model Context Protocol servers have quickly become the connective tissue between AI agents and the outside world — file systems, databases, APIs, internal tools, you name it. That convenience comes with a catch: the tools, prompts, and schemas an MCP server exposes are a new kind of attack surface, and most traditional scanners simply don't look there. MCPRadar is an open-source project built specifically to close that gap. Why this matters A recent academic study examining nearly 1,900 MCP servers found meaningful security issues in a surprising share of them — general vulnerabilities in roughly 7% and MCP-specific tool poisoning in another 5%. Tool poisoning, prompt injection hidden in tool descriptions, and quietly over-permissioned configurations are easy to miss because they don't look like a "normal" vulnerability — there's no CVE, no obvious buffer overflow, just a tool description that quietly tells an agent to do something it shouldn't. MCPRadar's whole premise is that this class of risk deserves the same rigor as any other part of your CI pipeline. What it actually scans MCPRadar isn't a single-purpose linter — it looks at an MCP server from several angles: Protocol inspection — enumerates tools, prompts, resources, and templates the server exposes, and checks server instructions for suspicious content. Source analysis — walks Python and JavaScript/TypeScript code looking for SSRF, unsafe deserialization, command/SQL injection, Trojan Source tricks, and mismatches between a tool's description and what its code actually does. Configuration review — flags poisoned MCP or agent configuration files, risky hooks, and overly broad permission grants. Supply chain checks — fetches packages without running install scripts, cross-references dependencies against OSV, and can emit a CycloneDX SBOM with hashes and provenance. Change monitoring — stores snapshots in SQLite and diffs them over time, classifying changes as cosmetic, behavioral, or security-relevant so sil

yatuk 2026-07-28 02:26 7 原文
AI 资讯 Dev.to

I was maxing my Claude 5-hour limit daily and still wasting weekly quota every night, so I built a tool that spends it while I sleep

Like a lot of you I hit the 5-hour cap most days. What actually annoyed me was realizing the weekly limit doesn't line up with that. Even capping out daily, I ended every week with quota unused. It expires overnight even after I paid for it. So I built claude-overnight . I queue questions during the day, /queue how do sqlite WAL checkpoints work? right inside Claude Code, and a scheduler runs them at night once my limits reset, through claude -p on the subscription. Morning brings markdown reports and a digest of what ran and what happened. Every job saves its claude session, so overnight resume <id> reopens the conversation that wrote the report. You can argue with it about its conclusions over coffee. Or overnight followup <id> "go deeper on X" and it continues tomorrow night. Coding tasks work too. They run in a throwaway git worktree on an overnight/* branch, only against repos I've explicitly trusted, so the agent never touches my working tree. Morning review is just git diff main..overnight/whatever . Since people will ask how it reads limits when there's no official API: Claude Code stores an OAuth token locally (Keychain on Mac, ~/.claude/.credentials.json elsewhere), and GET https://api.anthropic.com/api/oauth/usage with that token plus an anthropic-beta: oauth-2025-04-20 header returns your 5h and weekly utilization with reset times. Same trick the menubar trackers use. It's undocumented and the response shape already changed once while I was building this, so the tool survives without it. The design constraint I cared most about: don't eat my own morning quota. It won't start above 20% of the 5h window, stops at 60%, skips entirely past 80% weekly, rechecks between jobs. In the morning it opens a page in the browser with the whole batch on it — what ran, how long it took, the resume command for each one, and every report rendered inline so you're not clicking through files half-awake. Check it out at https://github.com/rohanprichard/claude-overnight Curio

rohanprichard 2026-07-28 02:23 5 原文
产品设计 Dev.to

Summer Log #3: A Message, Memories and Building a MikroTik Monitor

Every log has a story خب، روز سوم الان که دارم این لاگ رو می‌نویسم، روز تقریبا تموم شده و امروز از اون روزهایی بود که حس خوبی داشت اگر بخوام بهش نگاه کنم، می‌تونم بگم یکی از روزهای خوب ۱۴۰۵ بود البته امیدوارم بهترینش نباشه چون هنوز کلی برنامه داریم، کلی چیز هست که باید ساخته بشه و کلی روز بهتر قراره بیاد یک پیام غیرمنتظره دیروز ساعت 17:54 یک پیام دریافت کردم راستش آن لحظه خیلی آماده جواب دادن نبودم من معمولا پیام کسی را بی‌جواب نمی‌گذارم، حتی اگر ناراحت باشم یا فاصله‌ای ایجاد شده باشد اما بعضی وقت‌ها آدم نیاز داره سکوت کنه چند دقیقه، چند ساعت یا حتی بیشتر نه برای نادیده گرفتن، فقط برای اینکه بتونه با ذهن آرام‌تر و بی کینه تر جواب بده تایم نهار تصمیم گرفتم بخونم و جواب بدم هر چی نباشه اون کسی بود که موقع اعتراضات حالم رو پرسید حتی وقتی راجع به اون روز جمعه نکبت بار شنید با خطرات اون روزا برای عیادت من اومد ای کاش اون روزا بجای ساچمه تیر میخوردم ای کاش بعد دیدن اون کشتار من هم زنده نمی موندم شاید غریبه باشیم شاید دلخور باشم ولی خب هرگز خوبی ادم ها رو فراموش نمیکنم پیام طولانی بود خیلی طولانی و این دقیقا چیزی است که همیشه دوست داشتم آدم‌هایی که من را می‌شناسند می‌دانند که خودم هم معمولا جواب‌های کوتاه نمی‌دهم به نظرم نوشتن زیاد همیشه به معنی زیاد حرف زدن نیست گاهی یعنی برای توضیح دادن، برای فهمیده شدن و برای احترام گذاشتن وقت گذاشتی و این پیام هم همین حس را داشت نه فقط دفاع از خودت بلکه تلاش برای فهمیدن و توضیح دادن مرور خاطرات بعد از خواندن پیام، چند سال گذشته دوباره مرور شد بعضی آدم‌ها و بعضی روزها، حتی بعد از گذشت زمان، یک گوشه از ذهن باقی می‌مونن سال‌هایی که گذشت از ۱۳۹۹ تا ۱۴۰۲ سال‌هایی پر از تغییر، تجربه و اتفاق‌های مختلف پونه فرزانگان اختیاریه خب خیلی گذشته احساس پیری میکنم سال ۱۴۰۳ ارتباط کمتر شد و هر کسی مسیر خودش رو دنبال کرد تو کنکورت و من هم درگیر درد و دل با این باینری ها بودم اردیبهشت ۴۰۴ اتفاق‌هایی افتاد که شاید بهتر باشه فقط به عنوان تجربه به اون نگاه کنیم نه چیزی که هر روز دوباره مرور شه گاهی گذشته رو نمیشه تغییر داد و خب هممون اشتباه میکنیم بعد دوباره رسیدیم به یک نقطه جدید از ۴فروردین تا ۲۰ اردیبهشت امسال خب بازم شاید همون طوری که امروز گفتی هردو یه

Vobinax 2026-07-28 02:18 7 原文
AI 资讯 Dev.to

The Blinking Toilet Light and My `isProcessing` Flag Were Doing the Same Job

Introduction Hello from Japan! 🇯🇵 I am a professional truck driver teaching myself Python and web development while working toward a career transition into web engineering. This article records what I learned after approximately 122 hours of programming study , starting on May 12, 2026. Recently, I added a ripple animation effect to the answer buttons in my self-developed application: 🚛 DPT — Driver Personality Test https://qiita.com/tosane932/items/220d0f7d36bd79b2aa81 At first, I thought it would be a small visual improvement. However, while implementing it, I realized that the blinking light on my toilet control panel and a JavaScript flag named isProcessing were performing exactly the same role. This article explains that connection. It Started as Protection Against Repeated Clicks In DPT, clicking an answer button moves the user to the next question. In the original version, the next question appeared immediately after the button was clicked. However, this created a problem. If a user repeatedly clicked the button, the application continued advancing through the questions at the same speed. In an extreme case, someone could finish all 50 questions in only a few seconds. That would reduce the reliability of the personality test and could also create invalid answer records. To prevent this, I introduced a processing-state flag . let isProcessing = false ; testContainer . addEventListener ( " click " , ( event ) => { if ( isProcessing ) return ; const button = event . target . closest ( " .option-btn " ); if ( ! button ) return ; isProcessing = true ; createRipple ({ currentTarget : button , clientX : event . clientX , clientY : event . clientY }); const qIdx = Number ( button . dataset . qIndex ); const oIdx = Number ( button . dataset . oIndex ); setTimeout (() => { if ( oIdx === - 1 ) { handleAnswer ( qIdx , - 1 , " No answer " , 0 ); } else { const option = shuffledQuestions [ qIdx ]. shuffledOptions [ oIdx ]; handleAnswer ( qIdx , oIdx , option . text , optio

tosane932 2026-07-28 02:15 8 原文
AI 资讯 GitHub Blog

The harness is all you need (mostly)

A practical GitHub Copilot workflow for prototyping, planning, implementing, and reviewing software without chasing every new AI tool. The post The harness is all you need (mostly) appeared first on The GitHub Blog .

Burke Holland 2026-07-28 02:00 5 原文
AI 资讯 GitHub Blog

The harness is all you need (mostly)

A practical GitHub Copilot workflow for prototyping, planning, implementing, and reviewing software without chasing every new AI tool. The post The harness is all you need (mostly) appeared first on The GitHub Blog .

Burke Holland 2026-07-28 02:00 4 原文
工具 Hacker News Best

Canceling "Hey"

Article URL: https://chadnauseam.com/random/cancelling-my-hey Comments URL: https://news.ycombinator.com/item?id=49073007 Points: 233 # Comments: 207

ChadNauseam 2026-07-28 01:37 8 原文