The MCP Security Model: Trust Boundaries You Actually Have
MCP standardises connection, not trust. Here are the real boundaries in an MCP deployment and the attacks that cross them, with practical mitigations.
ReadPractical writing for developers building with large language models — how they work, how to pick one, and how to keep the bill predictable.
Agents, tool calling, and the loop that makes them useful.
MCP standardises connection, not trust. Here are the real boundaries in an MCP deployment and the attacks that cross them, with practical mitigations.
ReadAgents retry constantly, and most of it is wasted. How to tell a transport failure from a wrong decision, and what each one actually needs.
ReadTool output is the largest block of prompt content you never wrote. How to shape it so agents stay accurate, cheap and able to decide what to do next.
ReadTool definitions are prompt content the model reads on every turn. Design choices there change agent reliability more than model selection does.
ReadA flat log of model calls cannot explain a twenty-step run. How to shape spans, propagate context through subagents and async tools, and replay a run from its trace.
ReadThe most reliable agent improvement is refusing to accept completion until something verifies it. How to build a verifier that is worth trusting.
ReadAgent spend is not a per-call problem, it is a per-loop problem. Budgets, caching, tiering and circuit breakers that cap what a bad run can cost you.
ReadErrors are the normal case in an agent loop, not the exception. These are the recovery patterns that separate agents that finish from agents that spiral.
ReadLong agent sessions fail because context fills with noise. Here are the practical strategies for deciding what an agent should remember and what to drop.
ReadAgent failures are rarely reproducible, so logs are not enough. What to record per step, how to span a tool loop, and which metrics predict a bad run.
ReadReactive loops drift on long tasks and rigid plans break on contact with reality. Here are the planning strategies that work, and how to choose between them.
ReadAn agent that runs code needs a blast radius, not trust. How containers, gVisor and microVMs differ, and the network and credential controls that matter.
ReadShowing 49–60 of 74 articles