mcp
21 posts
- Cloudflare can now see some MCP traffic, and the gap is the point
Gateway's new experimental.is_mcp selector identifies MCP requests by protocol header. Cloudflare is clear that its absence proves nothing, which makes this a network inventory signal rather than a census of agent activity.
- Tailscale Aperture treats agent access as a change-control problem
Aperture is generally available. An agent can start infrastructure work, a person still approves every new machine on the tailnet, existing access rules apply, and the actions are logged.
- The robot arm will obey the limits you remembered to write down
Anthropic's Model Hardware Standard lets agents drive lab instruments over MCP, and enforces safety limits below the agent. The limits it enforces are the ones the device's owner thought to declare.
- WebMCP could make browser agents less clumsy. It also makes permission design unavoidable.
A proposed browser API gives AI agents structured access to specific tasks on a website, instead of leaving them to guess at the UI. The risk moves closer to the application's permission model.
- The Text Your Agent Reads Isn't the Text You See
Your AI can read instructions that are invisible to you. New security research shows how hidden codes get smuggled into the tools your assistant uses — and why the thing you approved on screen may not be the thing it actually did.
- MCP Just Changed Hands. Watch What Happens Next.
Anthropic donating MCP to the Linux Foundation is good governance — and a signal that the easy days of fast iteration are probably over.
- MCP Just Crossed the Chasm
This week, MCP went from developer protocol to mainstream integration layer — and most AI newsletters missed it.
- The New Shadow IT Isn't Employees Using ChatGPT
AI agents are generating mobile app traffic that security teams can't see. Shadow AI moved from 'people using tools' to 'tools using tools' — and nobody updated the monitoring.
- The Money Just Noticed the Agent Security Problem
Bessemer's new report on AI agent security says what practitioners have known for months. Now comes the flood.
- When Cisco Validates Your CLAUDE.md
Cisco's new MCP security gateway is the enterprise version of what power users already built out of necessity.
- Perplexity Is Learning What I Learned Six Months Ago
The Perplexity CTO says MCP eats 40-50% of your context window. Practitioners already knew this.
- Anthropic Built MCP, Got Everyone to Use It, Then Gave It Away
MCP just moved from Anthropic's project to shared industry infrastructure — and that changes the risk calculation for anyone building on it.
- AI Agent Security Is Doing the Deploy-First Thing Again
MCP is six months old and already has a CVSS 9.4 vulnerability. The security industry is scrambling. We've been here before.
- WordPress Just Opened the Floodgates
AI agents can now write and publish directly to WordPress. Quality control just became the only thing that matters.
- Box Is Using Moltbook as a Sales Pitch. That's Smart.
Enterprise vendors are turning the Moltbook API leak into a governance story — and the framing tells you where the market is heading.
- GitHub Added Secret Scanning to Its MCP Server. This Is What Good Security Integration Looks Like.
GitHub's MCP server now lets AI coding agents scan code for secrets through the same protocol they're already using. No extra tooling. No separate workflow.
- Proofpoint Just Built Security for MCP. That Tells You Everything.
Proofpoint's new Agent Integrity Framework monitors whether AI agents do what they were actually asked to do. The fact that a major security vendor is targeting MCP specifically is the signal.
- OWASP Published an MCP Security Guide. You Should Be Worried.
MCP adoption is outpacing security controls. OWASP and Microsoft both published governance guidance in February. That's not coincidence—it's alarm bells.
- Cloudflare Collapsed 2,500 API Endpoints Into 2 MCP Tools. Token Economics Matter.
Cloudflare's Code Mode demonstrates that MCP server design isn't about exposing more tools—it's about exposing fewer, smarter ones.
- AI That Actually Works Together
May 30th, 2025 Dear Reader, I’ve been putting Claude Sonnet 4 through its paces this week, and whilst the improved reasoning is impressive, what…
- 💾 The Download #007: Data vis in Claude, new service launch, what AI is saying about you and more.
#007 Hello Reader, it's good to see you. The holidays are fast approaching, and hopefully you will be able to plan some down time and a reset. When I…