4 ms·
Show HN: Mcpsnoop – Wireshark for MCP (transparent proxy and live TUI)
- kerlenton 3mo ago[flagged]
- atmanactive 3mo agoThis is awesome, thank you. What's missing now is an MCP for Wireshark.
- kerlenton 3mo agoThanks! Actually, there is already an MCP for Wireshark, for example https://github.com/0xKoda/WireMCP https://github.com/0xKoda/WireMCP
- atmanactive 3mo agoBingo! Great find. Thank you.
- InfraScaler 3mo agoYou can just get your agent to run tshark :)
- kerlenton 3mo agoHa, fair. tshark in a shell works fine, the only reason to wrap it is typed output and not handing the agent a raw shell.
- chopete3 3mo agoThis is awesome. Your comparison make it easy. This approach makes perfect sense to give 100% visibility into the back and forth. Is it possible to add a simple browser page to brows the data in a simple way?. Thank you.
- kerlenton 3mo agoThank you! Showing the data in a web page should definitely be possible. But I’m not sure if this matches the original idea I had, where the tool would run in the terminal only. Why do you feel the need to show the data in a web page? Is there anything missing in the CLI?
- yr_animesh 3mo agoIts really a great tool. The gap of visualization of calling the AI client is covered by your product!!
- kerlenton 3mo agoThanks a lot!
- tiku 3mo agoTo be fair, it is really simple to build your own proxy. I built a custom authentication layer with logging and limits for Dify MCP with just 2 prompts in Kimi. Later built it out with database limts etc.
- kerlenton 3mo ago[dead]
- iamgopal 3mo agoGreat. I dream to see MCP of MCP, discovery, installation, security and usage should be automatic.
- cidd 3mo agoI feel most of the comments here are from bots
- kerlenton 3mo agoMaybe, but I didn't do it. Perhaps people are boosting their karma?
- geraldsterling 3mo agoIt's getting bad. Definitely a hole that needs to be filled...
- westurner 3mo agoRemote debugging and post-mortem debugging support might be useful. There are many AI auditability proxies; awesome-auditable-ai: "A curated list of papers, tools, datasets, benchmarks, and standards for building, evaluating, and auditing reliable AI agents" https://github.com/yzhao062/awesome-auditable-ai https://github.com/yzhao062/awesome-auditable-ai Aegis and LiteLLM, for example, are pre-execution firewalls that add a cryptographic audit trail. https://github.com/Justin0504/aegis https://github.com/Justin0504/aegis
- kerlenton 3mo ago[dead]
- tomkow 3mo ago[flagged]
- dialsMavis 3mo agoCoward
- jing09928 3mo ago[flagged]
- mmakeev 3mo agoOne question about http mode, you carry authorization headers. Do you redact bearer tokens before captures hit the logs?
- kerlenton 3mo agoThere's nothing redacted because the header isn't collected in the first place. Under http mode, the proxy intercepts the JSON-RPC messages, but not their headers, so there's no way for the log to contain the Authorization header and the bearer passes through unlogged. The contents of the messages themselves aren't redacted, which means if the secret is in the payload, it'll end up in the trace. The trace stays on your machine, and if you don't want anything to go to the disk at all, use --no-trace.
- mmakeev 3mo agothanks! all clear
- geraldsterling 3mo agoMakes sense. Payload secrets are probably the scarier part anyway. Would a simple redact config make sense, like keys/patterns to scrub before writing traces?
- kerlenton 3mo ago[dead]
- rstagi 3mo ago"MCP Inspector [...] never sees the traffic between your client and your server." This line resonates a lot, what you're building makes sense to me! I had built something similar to track these interactions and turn them into a benchmark, I'm gonna try this out.
- kerlenton 3mo agoThanks, that means a lot. Would love to hear how it goes once you try it