Skip to main content

531 posts tagged with "AI agents"

AI agents and autonomous systems

View all tags

Read the AI agents and MCP guide

Falco's Prempti Is a Policy Layer for AI Coding Agents, Not Kernel Security: What It Catches and Misses
·Dora Noda·13 min

Falco's Prempti Is a Policy Layer for AI Coding Agents, Not Kernel Security: What It Catches and Misses

Falco's Prempti judges an AI coding agent's tool calls before they execute — but it never sees a syscall. A scenario-by-scenario map of what hook-level policy, eBPF monitoring, and microVM sandboxes each catch and miss on the deploy-from-chat path.

cybersecurity
AI agents
Model Context Protocol
self-hosting
Headlamp's Plugin Sprint Gave Kubeflow, Volcano, and Knative a GUI: Is It Ready to Be Your Fleet's Operator Console?
·Dora Noda·10 min

Headlamp's Plugin Sprint Gave Kubeflow, Volcano, and Knative a GUI: Is It Ready to Be Your Fleet's Operator Console?

Headlamp shipped GUI plugins for Cluster API, Volcano, Knative, and Kubeflow in summer 2026. A plugin-by-plugin scorecard — versions, capabilities, honest gaps — and what it means for a self-hosted fleet running AI-agent workloads.

Kubernetes
self-hosting
PaaS
AI agents
+1
Humans Missed 1 in 3 Threats Approving AI Agent Commands: What 409,000 Decisions Say About Human-in-the-Loop Deploy Guardrails
·Dora Noda·9 min

Humans Missed 1 in 3 Threats Approving AI Agent Commands: What 409,000 Decisions Say About Human-in-the-Loop Deploy Guardrails

Across 409,000 approve-or-deny decisions, human reviewers missed a third of malicious AI agent commands — and the credential-stealing ones slipped through three times as often as the obviously destructive ones. The numbers argue for sandboxes, scoped credentials, and policy engines ahead of the approve button.

AI agents
security
developer tools
engineering
15 Clean Releases, Then One Exfiltration Line: Lessons from the First Malicious MCP Server in the Wild
·Dora Noda·11 min

15 Clean Releases, Then One Exfiltration Line: Lessons from the First Malicious MCP Server in the Wild

In September 2025 the npm package postmark-mcp shipped fifteen clean releases, then added a one-line BCC backdoor in v1.0.16 — the first malicious MCP server caught in the wild. What the incident proves about version-history trust, plus a concrete checklist for teams installing third-party MCP servers and platforms distributing their own.

Model Context Protocol
AI agents
security
cybersecurity
MCP Won the Protocol War — the Lock-In Just Moved Up a Layer: A Self-Hoster's Field Test
·Dora Noda·10 min

MCP Won the Protocol War — the Lock-In Just Moved Up a Layer: A Self-Hoster's Field Test

MCP became the universal agent interface — and the lock-in moved into security policies, drift detection, and Skills libraries. A hands-on field test shows which moats self-hosting defeats and which one follows you home.

Model Context Protocol
AI agents
self-hosting
security
+1
10,000 MCP Servers Later: What Pinterest's Central Registry Teaches About Running Your Own Deploy Tools
·Dora Noda·12 min

10,000 MCP Servers Later: What Pinterest's Central Registry Teaches About Running Your Own Deploy Tools

Pinterest runs 66,000+ MCP tool calls a month through domain-specific servers behind a central registry. How the registry-plus-fleet pattern solves discovery and access control — and what it means for the deploy tools agents drive.

Model Context Protocol
AI agents
engineering
infrastructure
+1
MCP Streamable HTTP in Production: When Stateless Tool Calls Scale Cleanly and When a Deploy Agent Needs Session Affinity
·Dora Noda·10 min

MCP Streamable HTTP in Production: When Stateless Tool Calls Scale Cleanly and When a Deploy Agent Needs Session Affinity

AWS's FastMCP-on-ECS reference runs MCP servers stateless so any replica can answer any tool call, and the July 2026 spec revision deleted protocol-level sessions entirely. Here is that verdict mapped onto a deploy/rollback agent: which tools stay stateless, where multi-step state lives instead, and how idempotency keys keep privileged infrastructure actions safe across retries.

Model Context Protocol
AI agents
self-hosting
engineering
MCP Tasks and Multi-Round Trips: The Durable Deploy Contract an Agent-Operated PaaS Needs
·Dora Noda·11 min

MCP Tasks and Multi-Round Trips: The Durable Deploy Contract an Agent-Operated PaaS Needs

MCP's July 2026 spec adds asynchronous Tasks and Multi-Round Trip Requests. Together they form a durable deploy state machine: task handles instead of blocked calls, an approval boundary before production promotion, safe retry, cooperative cancel, and rollback as a first-class task.

PaaS
AI agents
Model Context Protocol
self-hosting
+1
Microsoft Agent 365 Goes GA and Starts Auto-Discovering the MCP Servers Nobody Registered
·Dora Noda·11 min

Microsoft Agent 365 Goes GA and Starts Auto-Discovering the MCP Servers Nobody Registered

Microsoft's Agent 365 platform went GA on May 1, 2026 with Shadow AI Discovery that surfaces unmanaged MCP servers through Defender and Intune. Here are the five governance controls it ships — and what a self-hosted PaaS must build itself, since Microsoft's discovery cannot see its fleet.

AI agents
Model Context Protocol
cybersecurity
self-hosting
Showing 235–243 of 531 posts