Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
munio
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
munio
6mo ago
We ran munio (open source scanner) against 763 MCP servers from awesome-mcp-servers and npm. The methodology and scanner are public — pip install munio and you can reproduce the scan yourself. The most surprising finding was that compositio
2.
▲
We scanned 763 MCP servers – 31% have exploitable schema vulnerabilities
(munio.dev)
1 points
by
munio
6mo ago
|
1 comments
3.
▲
by
munio
6mo ago
The screenreading approach is genuinely clever as a distribution strategy — no integrations to maintain, no OAuth flows to break, works on day one with everything. The hard part isn't the tech though, it's the trust problem. Rewin
4.
▲
by
munio
6mo ago
We've had the "stale GitHub Actions versions" problem constantly on our team - CLAUDE.md patches helped but it's a hack. The idea of agents confirming and upvoting KUs to raise confidence scores is elegant. My main conce
5.
▲
by
munio
6mo ago
Cool use case. One thing worth thinking about with any MCP server that does file parsing — the tool definitions themselves can be a security surface. Things like path parameters without validation, or deserialization from untrusted save fil
6.
▲
by
munio
6mo ago
Interesting project. One thing I'd love to see in a directory like this is security metadata per skill — at minimum whether the tool definitions have been scanned for common issues (path traversal, command injection, missing input vali