Skip to main content

531 posts tagged with "AI agents"

AI agents and autonomous systems

View all tags

Read the AI agents and MCP guide

10,000 MCP Servers Later, the Hard Part Isn't Building One — It's Being Found and Trusted
·Dora Noda·9 min

10,000 MCP Servers Later, the Hard Part Isn't Building One — It's Being Found and Trusted

MCP passed 10,000 public servers and 97 million monthly downloads in 2026 — but 52% of those servers are abandoned. Here's what building bex's own MCP server into that ecosystem actually requires: the protocol's stateless rewrite, the tool-poisoning threat class, and why shipping one isn't a differentiator anymore.

Model Context Protocol
AI agents
self-hosting
PaaS
+1
Backstage Ships MCP Tokens for Claude and Cursor: What Exposing a Golden-Path IDP to AI Agents Actually Requires
·Dora Noda·8 min

Backstage Ships MCP Tokens for Claude and Cursor: What Exposing a Golden-Path IDP to AI Agents Actually Requires

Backstage 1.43 lets Claude and Cursor call your golden-path Scaffolder actions with a short-lived, per-user token instead of a shared secret. Here's the actual config, the failure mode an unscoped action list creates, and what a self-hosted PaaS's own MCP server needs to copy.

Model Context Protocol
AI agents
self-hosting
PaaS
+1
Better-PaaS Ships Scoped Agent Tokens for Cursor and Claude Code — What an AGPL Self-Hosted PaaS Choosing Managed Databases Over bex's Non-Goal Reveals
·Dora Noda·8 min

Better-PaaS Ships Scoped Agent Tokens for Cursor and Claude Code — What an AGPL Self-Hosted PaaS Choosing Managed Databases Over bex's Non-Goal Reveals

Better-PaaS, a single-maintainer AGPL project, ships three-tier scoped agent tokens and seven MCP tools for Cursor and Claude Code — a concrete look at what that buys against bex's own coarser key model, and where Better-PaaS's bundled managed databases trade convenience for the high-availability story a single VPS can't back.

self-hosting
PaaS
AI agents
Model Context Protocol
+1
Three JavaScript Quirks, One CVSS 10.0 RCE: What n8n's Sandbox-Escape Chain Means for Every Agent Tool Wired to Your Cluster
·Dora Noda·9 min

Three JavaScript Quirks, One CVSS 10.0 RCE: What n8n's Sandbox-Escape Chain Means for Every Agent Tool Wired to Your Cluster

Three individually-harmless gaps in n8n's JavaScript sandbox chained into a CVSS 10.0 RCE that reached every stored credential and, on shared instances, the Kubernetes cluster underneath. Here's the exploit chain and what it means for any tool that hands an agent a general-purpose sandbox.

cybersecurity
AI agents
Kubernetes
self-hosting
+1
The NSA Just Published a Threat Model for MCP: What It Means for Your Deploy Agent
·Dora Noda·9 min

The NSA Just Published a Threat Model for MCP: What It Means for Your Deploy Agent

The NSA's AI Security Center named four structural risks in MCP's design — and every one already has a real 2026 incident behind it. Here's what each means concretely for a self-hosted MCP server with deploy and rollback authority.

Model Context Protocol
AI agents
security
self-hosting
+1
Gitpod Bet the Company on Self-Hosted Agent Infra — Then OpenAI Bought It
·Dora Noda·8 min

Gitpod Bet the Company on Self-Hosted Agent Infra — Then OpenAI Bought It

Gitpod rebranded to Ona and went self-hosted-only in September 2025. Nine months later OpenAI bought it for Codex. Here's what a hyperscaler choosing to buy customer-owned execution instead of building it actually signals.

AI agents
self-hosting
openai
acquisitions
+1
What a Zanzibar-Style Relationship Graph Buys a Deploy MCP Server Over a Scoped API Key
·Dora Noda·8 min

What a Zanzibar-Style Relationship Graph Buys a Deploy MCP Server Over a Scoped API Key

AuthZed is pitching SpiceDB's relationship-graph authorization for AI agents. Here's the actual SpiceDB schema for a deploy/rollback MCP server, what it can check that a scoped API key can't, and whether running it is worth the operational cost.

Model Context Protocol
AI agents
self-hosting
security
+1
SPIRE Needs Your Fleet's Shape in Advance. An Orchestrator Spawning Sub-Agents Doesn't Have One.
·Dora Noda·8 min

SPIRE Needs Your Fleet's Shape in Advance. An Orchestrator Spawning Sub-Agents Doesn't Have One.

SPIRE requires every workload to be pre-registered before it can attest — a model that breaks the moment an orchestrator spawns sub-agents on demand. Here's the actual registration race, the ClusterSPIFFEID fix, and what it still doesn't solve.

security
cryptography
identity
AI agents
+1
Your Deploy Agent Has the Same Privileges as a Human Push — and No Insurance
·Dora Noda·10 min

Your Deploy Agent Has the Same Privileges as a Human Push — and No Insurance

AIUC-1 and California's AB 316 just made 2026 the year AI agent liability got real, while insurers quietly excluded it from standard coverage. Here's what's actually covered, what isn't, and the audit-trail and permission design a deploy-from-chat platform needs today.

AI agents
compliance
PaaS
self-hosting
+1
Showing 379–387 of 531 posts