AgentPod is building a private, secure device for your AI agent.The AgentPod device is coming.Coming soonBe first
We checked this and rejected itsecurity

mcp-hacker-news: why it is not safe to use

We did not find security or privacy issues in the inspected mcp-hacker-news repo; it passed review based on the code and files we checked.

What we found

Our review of `paabloLC/mcp-hacker-news` did not identify a security or privacy issue that would block use in AgentPod. In the inspected repository files, we found no hidden or disguised prompt instructions, no hardcoded credentials or API keys, and no obfuscated or minified payloads. The code appears to act as a read-only MCP server that accepts JSON-RPC messages over standard input and fetches data from the official Hacker News API.

We also did not find signs of undisclosed data flows. Based on the code we inspected, requests go to the named Hacker News API endpoint and results are returned to the connected MCP client. We found no logic for deleting, overwriting, publishing, changing permissions, escalating privileges, or reading local credentials such as environment secrets, browser data, SSH keys, or keychains.

What to do instead

If you choose to use this skill, treat it as a read-only connector for Hacker News content and keep normal MCP safeguards in place. Review any future code changes, pin versions where possible, and confirm that runtime behavior continues to match the current implementation and documented API usage.

Want the same outcome, safely? Use our checked skill instead.

Source: https://github.com/paabloLC/mcp-hacker-news

We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.

Copied to clipboard. Paste it into your AI (ChatGPT, Claude, or your agent) to add the skill.