266 posts tagged with "Model Context Protocol"
Content about the Model Context Protocol (MCP)

Fail Closed Before the Agent Acts: What Conduct's Guard-Before-Every-Tool-Call Model Means for Governing Deploy Agents
Conduct puts a fail-closed policy gate — block, warn, audit, or inject — in front of every MCP and shell action an agent takes. A decision table for deploy, rollback, and secret-read tools, plus which production actions still need a human.

MCP at 97 Million Downloads: the Protocol Won, but Sessions and Sandboxes Are Still Open Problems
MCP hit 97 million monthly downloads and 10,000+ production servers — but stateful sessions still break behind load balancers and every agent framework ships its own sandbox. What the adoption numbers prove, and the two gaps they don't.

One in Five MCP Access Policies Is Broken or Missing: The Audit to Run Before Agents Touch Your Deploy Pipeline
One in five MCP access policies is broken or missing, Splunk's MCP server leaked tokens in cleartext until v1.0.3, and the July 2026 spec rebuilt authorization from scratch. What it means for deploy tools exposed to agents, and the ten-check audit to run first.

MCP's July 2026 Authorization Hardening: How RFC 9207 Issuer Checks Protect Agents That Hold Deploy Keys
The MCP 2026-07-28 specification closes the authorization-server mix-up attack with mandatory RFC 9207 issuer validation and issuer-bound credentials. Here is how the attack steals an agent's deploy credentials, and the server-side checklist for infrastructure MCP servers.

MCP's July 2026 Revision Redesigns the Minutes-Long Tool Call: Tasks, MRTR, and server/discover Explained
MCP's July 28, 2026 revision moves long-running tools to a pollable Tasks extension, replaces server callbacks with multi round-trip requests, and mandates server/discover — a deploy-tool-grounded walkthrough with sequence sketches and a migration checklist.

OpenCost's Built-In MCP Server Turns Cost Allocation Into an Agent-Callable Tool
OpenCost's built-in MCP server exposes Kubernetes cost allocation as agent-callable tools. Here is the exact tool surface, a worked tenant-cost query, and the scoping rules that keep read-only cost data safe on a multi-tenant fleet.

Railway's Q2 Changelog Is the Deploy-From-Chat Playbook: Sandboxes, SSH, and Private Networking in Dependency Order
Railway's May–June 2026 changelog shipped standard SSH, an agent sandbox VM, zero-install SSH onboarding, and scriptable private networking — in exactly the dependency order a deploy-from-chat platform needs. A dated reading of the quarter plus a five-step build order for self-hosting it.

Render's MCP Server Just Set the Deploy-From-Chat Baseline: OAuth, trigger_deploy, and What Your Self-Hosted Fleet Must Match
Render's July 2026 MCP updates — one-click OAuth and a hardened trigger_deploy — define what agent-operated deploys look like. A 25-tool inventory of the baseline plus a parity checklist for matching deploy-from-chat on machines you own.

StackQL v0.11 Turns Every Agent Cloud Query Into an OpenTelemetry Record: What That Buys Your Fleet's Audit Trail
StackQL v0.11 speaks MCP revision 2026-07-28 and emits its agent audit log as OTLP records. The exact collector config that ingests it with no transform, the stateless-HTTP tradeoff, and what remains before inventory queries become deploy authority.