Viewing profile — XiaHua
XiaHua
HN member- Joined
- Tue, May 13, 2025, 3:55 AM UTC
- HN karma
- 36
- Public activity
- 16 items
- HN profile
- View on Hacker News ↗
About XiaHua
Recent public activity
-
comment
Comment #48988614
We monitor both the app layer and the MCP servers. We run a hosted version of https://github.com/traceforce/mcp-xray in our backend to constantly pentest MCPs and their supply chai…
-
comment
Comment #48988597
It's always a trade-off between serverless and how much customization we want. The Kong plug-in is easy to customize for us.
-
comment
Comment #48953706
Thank you!
-
comment
Comment #48953278
Good luck to your startup as well!
-
comment
Comment #48949162
What do you use to host your public MCP server? We use Kong and they have lots of security plug-ins to choose from. For example https://developer.konghq.com/plugins/bot-detection/
-
comment
Comment #48942871
I'm curious how your pentesting tool handles the frequent updates in AI app behaviors and MCP APIs without overwhelming false positives? ---> Our pentest tool has a "secret" step c…
-
comment
Comment #48942036
oh and to add on this, MCP gateways work mostly with remote MCPs only. For the stdio ones, we still need local agents to take care of the controls.
-
comment
Comment #48941939
Thanks for reaching out out. We have one already https://traceforce.trust.cyberbase.ai/
-
comment
Comment #48941910
Yes you are spot on! On-device agents can only do so much. We integrate with popular gateways such as Kong to bring MCP controls. We primarily manage the registries for MCPs with v…
-
comment
Comment #48941116
That's a great example. It's exactly the kind of behavior we think deserves more attention. It's not a traditional vulnerability but it can significantly influence an agent's decis…
-
comment
Comment #48939450
I will definitely checkout Runlayer Watch in depth. It seems that it works with coding agents but not web-based agents yet. We've had customers comparing the two solutions. They li…
-
comment
Comment #48937975
Runlayer can be a fit once you know what you want to put behind an MCP gateway. The challenge we hear from customers is that they don't know what AI apps, MCPs, or tools their empl…
-
comment
Comment #48937908
Thanks for the feedback! I agree that DROP TABLE executes remotely. The key point is that the decision to invoke the tool is made by coding agents like Claude Code. Traceforce capt…
-
comment
Comment #48937131
We are also curious to ask what existing tools are folks using to gain visibility into what's running out there?
-
story
Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps
Hey HN, we’re Xia and Varun, the founders of Traceforce ( https://www.traceforce.ai/ ). Traceforce provides visibility and control over AI apps such as ChatGPT, Claude etc directly…
- story