Skip to main content

266 posts tagged with "Model Context Protocol"

Content about the Model Context Protocol (MCP)

View all tags

Read the AI agents and MCP guide

The NSA Just Published a Threat Model for MCP: What It Means for Your Deploy Agent
·Dora Noda·9 min

The NSA Just Published a Threat Model for MCP: What It Means for Your Deploy Agent

The NSA's AI Security Center named four structural risks in MCP's design — and every one already has a real 2026 incident behind it. Here's what each means concretely for a self-hosted MCP server with deploy and rollback authority.

Model Context Protocol
AI agents
security
self-hosting
+1
Railway's New MCP Server Has 7 Tools. bex's Shipped One Has 13 — and Still Can't Deploy
·Dora Noda·8 min

Railway's New MCP Server Has 7 Tools. bex's Shipped One Has 13 — and Still Can't Deploy

Railway's remote MCP server ships 7 tools and a one-line agent install; bex's already-shipped MCP server exposes 13. Here's what each actually lets an agent do unattended, and the one deploy verb bex still owes its own roadmap.

Model Context Protocol
self-hosting
PaaS
infrastructure
+1
What a Zanzibar-Style Relationship Graph Buys a Deploy MCP Server Over a Scoped API Key
·Dora Noda·8 min

What a Zanzibar-Style Relationship Graph Buys a Deploy MCP Server Over a Scoped API Key

AuthZed is pitching SpiceDB's relationship-graph authorization for AI agents. Here's the actual SpiceDB schema for a deploy/rollback MCP server, what it can check that a scoped API key can't, and whether running it is worth the operational cost.

Model Context Protocol
AI agents
self-hosting
security
+1
Friendly Fire: The AI Security Review That Executes the Attack It's Supposed to Catch
·Dora Noda·9 min

Friendly Fire: The AI Security Review That Executes the Attack It's Supposed to Catch

AI Now Institute's Friendly Fire exploit turns Claude Code and Codex's own security reviews into remote code execution — here's how it works and what it means for scoping AI agent permissions on a deploy pipeline.

security
cybersecurity
AI agents
Model Context Protocol
+1
GitHub Copilot's Worktree Isolation Is Not a Sandbox — Why That Matters for Deploy-Authority Agents
·Dora Noda·8 min

GitHub Copilot's Worktree Isolation Is Not a Sandbox — Why That Matters for Deploy-Authority Agents

GitHub's Copilot app isolates parallel agent sessions with git worktrees, not sandboxes — fine for code edits, but not enough for an MCP server that can deploy and rollback real infrastructure. Here's the concrete difference and what it means for agent-operated PaaS platforms.

GitHub Copilot
self-hosting
PaaS
Model Context Protocol
+1
Pinterest Ran 66,000 MCP Tool Calls a Month — Here's the Gate Your Deploy Agent Needs
·Dora Noda·9 min

Pinterest Ran 66,000 MCP Tool Calls a Month — Here's the Gate Your Deploy Agent Needs

Pinterest's production MCP fleet handled 66,000 tool calls a month across 844 users. Here's the registry-and-gate architecture behind those numbers, and the concrete rate-limit and audit-retention policy a deploy-from-chat PaaS should ship on day one.

Model Context Protocol
AI agents
self-hosting
PaaS
+1
Your Deploy Agent's MCP Server Is a Trust Boundary — Here's the Threat Model
·Dora Noda·9 min

Your Deploy Agent's MCP Server Is a Trust Boundary — Here's the Threat Model

A malicious MCP server already backdoored a mail pipeline in the wild. Here's the threat model for what happens when the same protocol holds your deploy and rollback credentials — and the scoping, gating, and logging practices that actually bound the damage.

Model Context Protocol
security
AI agents
self-hosting
+1
Cursor and Windsurf Can Now Run Your Code in the Cloud. Neither One Can Ship It.
·Dora Noda·9 min

Cursor and Windsurf Can Now Run Your Code in the Cloud. Neither One Can Ship It.

Cursor's Cloud Agents and Windsurf's Devin handoff both run your code in a sandboxed cloud VM and hand back a PR. Here's the documented, vendor-confirmed line where that stops and deploying starts — and what actually closes it.

Cursor
Windsurf
Model Context Protocol
AI agents
+1
AWS Open-Sourced the Exact MCP Governance Layer Snowflake Just Paid to Acquire
·Dora Noda·9 min

AWS Open-Sourced the Exact MCP Governance Layer Snowflake Just Paid to Acquire

Snowflake just paid an undisclosed sum to acquire Natoma's MCP governance gateway. AWS's Apache-2.0 mcp-gateway-registry already does the same identity, policy, and audit job — self-hosted on EKS, ECS, or a single Docker Compose file.

Model Context Protocol
self-hosting
PaaS
AI agents
+1
Showing 217–225 of 266 posts