266 posts tagged with "Model Context Protocol"
Content about the Model Context Protocol (MCP)

One API Key vs 7,000 Tools: Where a Self-Hosted PaaS's MCP Server Should Land
A homelab MCP bridge runs your infrastructure behind one API token; Arcade's engine vaults per-user OAuth behind 7,000 tools. The head-to-head operator math at three team sizes, and where a self-hosted PaaS should land between them.

One Config Field, 12,000 Exposed Boxes: What Flowise's CustomMCP RCE Teaches Anyone Exposing Agent Tools
Flowise's CustomMCP node turned a config string into remote code execution on 12,000+ internet-exposed instances. The anatomy of CVE-2025-59528, the sibling CVEs proving it is a pattern, and a six-rule checklist for anyone running an MCP or agent-tool surface.

Shipping a Deploy-Authority MCP Server on Golf: What the Framework Owns and What You Still Build
Golf, a production MCP server framework on FastMCP 4.0, owns auth, telemetry, and transport so you write only agent logic. Here is the exact framework-vs-platform split for an MCP server that deploys to production — plus the credential scoping, deploy API, and audit log no framework builds for you.

Hoplite and the Cloud Coding-Agent Wave: What You're Really Renting When Your Agent Setup Moves Off Your Laptop
Hoplite moves your coding-agent setup — sessions, memories, MCP servers — onto rented cloud sandboxes for $99/seat. A bundle inventory, the lock-in shape, worked rent-vs-own math at 1/5/20 developers, and the five-component self-hosted equivalent.

Kagent Brings CRD-Native AI Agents to Kubernetes: What It Means for a Self-Hosted PaaS
Kagent turns AI agents into Kubernetes objects you version, roll out, and inspect with kubectl. Here is what the Agent CRD, MCP tool servers, and A2A teams replace on a self-hosted PaaS roadmap — and where the platform still owns the problem.

30+ MCP CVEs in Two Months: What the Early-2026 Vulnerability Wave Means for Your Deploy MCP Server's Supply Chain
More than 30 MCP CVEs landed in the first two months of 2026 — most in proxies, registries, and SDKs, not tool code. What the wave teaches teams shipping a deploy MCP server, and the seven-row supply-chain checklist that falls out of it.

MCP's 2026 Enterprise-Readiness Push: Audit Trails, SSO, and Gateway Patterns for Agent Infrastructure You'd Otherwise Build Yourself
MCP hit 97M monthly downloads while shipping without a governance story. What the July 2026 spec hardened, what a production gateway must still add, and what vendors charge for.

MCP Joins the Linux Foundation: What Neutral Governance and Server Cards Mean for Shipping a Deploy Server Today
MCP is now neutral Linux Foundation infrastructure with 97M monthly SDK downloads — here is why that plus the stateless 2026-07-28 spec means you should ship your deploy-from-chat MCP server now, and treat Server Cards as a distribution upgrade, not a blocker.

MCP Multi-Round Trips: Human Approval Gates for Agent-Initiated Production Deploys
MCP's July 2026 release lets a server pause mid-call and ask a human to approve the exact plan before acting. Here is the four-step deploy gate — plan, digest-bound approval, single-use execution, auditable receipt — that replaces standing agent permission.