266 posts tagged with "Model Context Protocol"
Content about the Model Context Protocol (MCP)

15 Clean Releases, Then One Exfiltration Line: Lessons from the First Malicious MCP Server in the Wild
In September 2025 the npm package postmark-mcp shipped fifteen clean releases, then added a one-line BCC backdoor in v1.0.16 — the first malicious MCP server caught in the wild. What the incident proves about version-history trust, plus a concrete checklist for teams installing third-party MCP servers and platforms distributing their own.

MCP Won the Protocol War — the Lock-In Just Moved Up a Layer: A Self-Hoster's Field Test
MCP became the universal agent interface — and the lock-in moved into security policies, drift detection, and Skills libraries. A hands-on field test shows which moats self-hosting defeats and which one follows you home.

10,000 MCP Servers Later: What Pinterest's Central Registry Teaches About Running Your Own Deploy Tools
Pinterest runs 66,000+ MCP tool calls a month through domain-specific servers behind a central registry. How the registry-plus-fleet pattern solves discovery and access control — and what it means for the deploy tools agents drive.

MCP Streamable HTTP in Production: When Stateless Tool Calls Scale Cleanly and When a Deploy Agent Needs Session Affinity
AWS's FastMCP-on-ECS reference runs MCP servers stateless so any replica can answer any tool call, and the July 2026 spec revision deleted protocol-level sessions entirely. Here is that verdict mapped onto a deploy/rollback agent: which tools stay stateless, where multi-step state lives instead, and how idempotency keys keep privileged infrastructure actions safe across retries.

MCP Tasks and Multi-Round Trips: The Durable Deploy Contract an Agent-Operated PaaS Needs
MCP's July 2026 spec adds asynchronous Tasks and Multi-Round Trip Requests. Together they form a durable deploy state machine: task handles instead of blocked calls, an approval boundary before production promotion, safe retry, cooperative cancel, and rollback as a first-class task.

Microsoft Agent 365 Goes GA and Starts Auto-Discovering the MCP Servers Nobody Registered
Microsoft's Agent 365 platform went GA on May 1, 2026 with Shadow AI Discovery that surfaces unmanaged MCP servers through Defender and Intune. Here are the five governance controls it ships — and what a self-hosted PaaS must build itself, since Microsoft's discovery cannot see its fleet.

The OpenClaw Operator's Default-Deny Baseline: What One CRD Can (and Cannot) Contain
The OpenClaw Kubernetes operator packs non-root pods, dropped capabilities, and a default-deny NetworkPolicy into one install — a solid floor for running AI agents in-cluster. But Pod hardening stops at the process boundary: prompt injection, over-broad MCP credentials, and destructive-tool authorization need a governance layer no CRD provides.

Red Hat OpenShift AI Bakes In MCP — and the Bottleneck Moves to Discovery at 10,000 Servers
Red Hat is baking MCP into OpenShift AI as governed infrastructure — Playground validation, a verified catalog, a lifecycle operator, and a gateway. Why the agent tooling gap moved from protocol to discovery at 10,000+ servers, and a six-item checklist for a self-hosted platform's own MCP server.

Zerops's $2M Bet: Your Coding Agent Is the PaaS Customer Now
Zerops raised $2M to build a PaaS control plane for AI coding agents. How its ZCP work loop — live state, deploy evidence, behavior proof — compares to Render and Railway, plus a five-item MCP checklist for self-hosted platforms.