527 posts tagged with "AI agents"
AI agents and autonomous systems

Rubrik Just Gave Enterprise Agents a Governed MCP Path Into Its Security Cloud: Steal the Governed-Tool Pattern for Your Infra MCP Server
Rubrik's September 2026 MCP launch gave enterprise agents a governed path into backup and recovery workflows — narrow tools, per-call scoped tokens, and server-side policy instead of ambient API authority. What the governed-tool pattern means for a deploy/rollback/log MCP server, and the six controls to ship on day one.

Shadow AI in the Pipeline: What to Audit From Laptop to Kubernetes Before Unvetted AI Becomes a Supply-Chain Bridge
Unmanaged AI tools now sit at every stage from developer laptop to production cluster. A stage-by-stage audit of what to check and which open-source controls clamp each risk on a build fleet you own.

Vercel's fingerprintTools and detectToolDrift: The First Drift-Detection Primitives for MCP Tool Execution
Vercel's AI SDK added fingerprintTools and detectToolDrift to catch MCP servers silently mutating approved tool definitions. Here is how the pinning works, the behavior-swap hole it leaves open, and what a self-hosted deploy MCP server should adopt.

The Agentic Enterprise's Second Platform User: Designing Golden Paths That Both Developers and Deploy Agents Can Safely Consume
AI agents now provision, deploy, and investigate incidents alongside developers. A side-by-side comparison of a human-only portal with a machine-readable golden path, and the four contracts that make deploy from chat safe.

One Shared Quota Took Down Every Connector: What a 402 on MCP Initialize Teaches About Self-Hosting Agent Tools
On September 9, 2026, one exhausted shared quota answered MCP initialize with HTTP 402 and took every OptimNow connector down at once. The 14-file move to Fly.io scale-to-zero is a complete template for self-hosting production agent tools — here is the incident anatomy and the checklist.

CI Gets an MCP Server: What TeamCity's and Dooor OS's Deploy-via-MCP Tools Mean for a PaaS API That Agents Still Have to Scrape
TeamCity and Dooor OS now expose builds, deploys, and logs as MCP tools. Here is what they expose, why agents will operate your platform with or without you, and the checklist for a versioned, scoped, auditable agent interface.

Detectify Turned Its Scanner Into an Agent Tool: What 'Call the Scanner Like a Test Runner' Means for Your Deploy Pipeline
Detectify's May 2026 MCP Server hands security findings to coding agents as structured tasks with validation scans. How the Find & Fix loop works, what a scan phase between build and promote looks like for a git-push PaaS, and what stays human.

Your Sandbox Is an L2 Guest: What E2B's Nested Firecracker Really Costs vs Bare Metal
E2B's sandboxes run as L2 guests on rented GCP VMs. Fingerprint data, latency benchmarks, and a line-by-line bill recompute show where renting wins — and the roughly 300 sandbox-hour crossover where owned hardware takes over.

Firecracker's First Escape CVEs: What CVE-2026-5747 and CVE-2026-1386 Mean for MicroVM Sandboxes
Firecracker's zero-escape-CVE record broke twice in 2026: an out-of-bounds write in the virtio-pci transport and a symlink overwrite in the jailer. What both bugs mean for teams running AI-agent sandboxes on microVMs, and the patching checklist that keeps the isolation story intact.