Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Pirating the Pirates (mubi.com)
    17comments
  2. 13 Months Sober (2025) (bobbytables.io)
    35comments
  3. Hijacking the PS5's RTMP Stream (yashgarg.dev)
    3comments
  4. Parley: Federated, decentralised chat that speaks plain IRC (mills.io)
    112comments
  5. What Heraldry and Mon Can Teach Us About Building Visual-Identity Generators (benovermyer.com)
    10comments
  6. Show HN: HN.watch – Videos of all Hacker News posts (hn.watch)
    2comments
  7. The problem is not AI code, but not knowing about system architecture or intent (ssp.sh)
    149comments
  8. MongoDB CEO resigns to join Meta (reuters.com)
    119comments
  9. Cf: The Agentic CLI for the Cloudflare API (cloudflare.com)
    1comments
  10. 37,500 border drawings: a map of the world as people remember it (habibicode.org)
    31comments
  11. Coding Is Not Solved (alexewerlof.com)
    302comments
  12. Show HN: PaperMono, e-ink fridge magnet shopping list with mobile web page (github.com/seamusc)
    36comments
  13. What Would a Serious AI Product Look Like? (glyph.im)
    18comments
  14. Footguns with Postgres "at time zone 'UTC'" (bookofrevenue.com)
    73comments
  15. Owed a billion dollars in Nvidia stock (colo.to)
    418comments
  16. Kids turned low-traffic NPR Spotify comments into a secret group chat (thisamericanlife.org)
    72comments
  17. Show HN: Hntui – A TUI for Hacker News (github.com/ahmd-sh)
    44comments
  18. Ember-1 (fireworks.ai)
    239comments
  19. Show HN: Free alternative to graphics design giants (scissor.studio)
    17comments
  20. When did Google get so weird? (sancho.bearblog.dev)
    897comments
  21. Nissan's third generation e-POWER powertrain (nissan-global.com)
    305comments
  22. How Pew Research Center is – and is not – using AI in our work (pewresearch.org)
    1comments
  23. Solving a corn puzzle with CP-SAT (thill.me)
    2comments
  24. Thinking fast and slow in AI: The role of metacognition (2021) (arxiv.org)
    65comments
  25. Driver Ticketed for No Insurance Just Because Flock (YC 2017) Said She Didn't (techdirt.com)
    —discuss
  26. Self-Hosting on the Dark Web (alvarezrosa.com)
    106comments
  27. Malleable software: Restoring user agency in a world of locked-down apps (2025) (inkandswitch.com)
    69comments
  28. Alan Kay's answer to “Did the ENIAC have a BIOS”? (quora.com)
    61comments
  29. Guitar amp and effects pedal built on the Waveshare ESP32-S3-Touch-AMOLED-2.06 (github.com/dashersw)
    73comments
  30. Functional Mechanical Sympathy [video] (youtube.com)
    11comments

Show HN: Mcpsnoop – Wireshark for MCP (transparent proxy and live TUI)

64 pointsby 2mo agogithub.com
21 comments
2mo agoHN ↗

This is awesome, thank you. What's missing now is an MCP for Wireshark.

2mo agoHN ↗

You can just get your agent to run tshark :)

2mo agoHN ↗

Ha, fair. tshark in a shell works fine, the only reason to wrap it is typed output and not handing the agent a raw shell.

2mo agoHN ↗

This is awesome. Your comparison make it easy. This approach makes perfect sense to give 100% visibility into the back and forth.

Is it possible to add a simple browser page to brows the data in a simple way?. Thank you.

2mo agoHN ↗

Thank you! Showing the data in a web page should definitely be possible. But I’m not sure if this matches the original idea I had, where the tool would run in the terminal only. Why do you feel the need to show the data in a web page? Is there anything missing in the CLI?

2mo agoHN ↗

Its really a great tool. The gap of visualization of calling the AI client is covered by your product!!

2mo agoHN ↗

To be fair, it is really simple to build your own proxy. I built a custom authentication layer with logging and limits for Dify MCP with just 2 prompts in Kimi. Later built it out with database limts etc.

2mo agoHN ↗

Great. I dream to see MCP of MCP, discovery, installation, security and usage should be automatic.

2mo agoHN ↗

Maybe, but I didn't do it. Perhaps people are boosting their karma?

2mo agoHN ↗

It's getting bad. Definitely a hole that needs to be filled...

2mo agoHN ↗

One question about http mode, you carry authorization headers. Do you redact bearer tokens before captures hit the logs?

2mo agoHN ↗

There's nothing redacted because the header isn't collected in the first place. Under http mode, the proxy intercepts the JSON-RPC messages, but not their headers, so there's no way for the log to contain the Authorization header and the bearer passes through unlogged. The contents of the messages themselves aren't redacted, which means if the secret is in the payload, it'll end up in the trace. The trace stays on your machine, and if you don't want anything to go to the disk at all, use --no-trace.

2mo agoHN ↗

Makes sense. Payload secrets are probably the scarier part anyway. Would a simple redact config make sense, like keys/patterns to scrub before writing traces?

2mo agoHN ↗

"MCP Inspector [...] never sees the traffic between your client and your server." This line resonates a lot, what you're building makes sense to me! I had built something similar to track these interactions and turn them into a benchmark, I'm gonna try this out.

2mo agoHN ↗

Thanks, that means a lot. Would love to hear how it goes once you try it