Skip to content

#MCP/tool use

0 items today
10/6Tue
  1. DEV Community · MCP76

    How AI agents actually use your MCP server: five failure modes you won't see in logs

    The author instrumented a demo ticket-booking MCP server with a self-built tool called mcpspan and identified five kinds of agent invocation problems that never show up in logs: agents guessing tool names that don't exist; parameters that don't match the schema and get rejected by the SDK before the handler runs; parameter types misunderstood because of how the tool description is worded; retry loops that keep hitting the same parameter; and responses so large they eat into the context window.

    Why it matters: The author used a self-built MCP analysis tool to empirically surface five failure modes in agent calls that logs don't reveal, and these can be adapted to troubleshoot your own MCP server.

  2. DEV Community · MCP78

    Prompt injection is a data-plane problem: move the boundary from the model to the tool call.

    The author argues that prompt injection shouldn't be solved by making models smarter; instead, just as SQL injection is handled with parameterized queries, the boundary should be drawn where the agent executes actions.

    Why it matters: The author draws an analogy between prompt injection and SQL injection, arguing for moving the boundary from the model to the tool-call layer, and lays out a practical approach with a strategy layer and separate read and write phases.

  3. DEV Community · MCP82

    Skills Are Not Tools: Why I Gave My Coding Agent 11 MCP Servers and It Fell Apart

    In February I hooked up 11 MCP Servers to my coding agent. Just the tool list in an empty session ate up 34,000 tokens, with Datadog alone contributing over two hundred tools. The agent got slower and kept picking the wrong tools.

    Why it matters: I'm writing this up because 11 MCP Servers of my own blew up my context, and it showed me that tools and knowledge belong in different containers.

  4. DEV Community · MCP36

    Bifrost 开源 AI 网关推出企业级 MCP Gateway,治理 MCP 工具访问

    Bifrost 开源 AI 网关新增企业级 MCP Gateway,把 MCP 工具访问纳入控制平面治理。它通过访问配置文件、虚拟 MCP 服务器和工具级策略,按请求、客户端或虚拟 key 过滤工具,让工作负载只能发现和调用被授权的动作。Bifrost 默认不自动执行模型返回的工具调用,需应用审核后显式调用 /v1/mcp/tool/execute。

    Awaiting translation

  5. DEV Community · MCP58

    MCP 与自定义 REST 工具的安全对比及最新 MCP 架构

    文章对比了 MCP 与自定义 REST 工具在安全上的差异,指出 MCP 只标准化通信,认证、授权、最小权限、输入校验和监控仍需应用与后端自行实现。文中介绍了当前定稿的 MCP 规范 2026-07-28 的关键变化,包括无状态协议设计、server/discover、Streamable HTTP、多轮往返请求和 Tasks 扩展,并说明本地仍常用 stdio。

    Awaiting translation

  6. Reddit · ClaudeCode / Codex / VibeCoding22

    AI 编程智能体是否正在制造现有工具难以应对的安全问题?

    有开发者在 Reddit 上征集 Claude Code、Codex、Cursor 等 AI 编程智能体的实际安全实践,覆盖运行前扫描恶意 skill、MCP server 与传递依赖,AI 生成 PR 的安全检查与人工审查,以及运行中的工具调用监控、文件系统/网络/凭证访问限制和沙箱隔离。提问者更关注真实事故、险情和现有工具的缺口,并追问提示词注入是否来自 README、skill 或依赖文件。

    Awaiting translation

  7. DEV Community · MCP78

    Anonymous health checks on 78 registry MCP servers: 51.3% complete the full call sequence

    Pennyforge ran anonymous health checks on the 78 servers that responded to initialize out of 186 endpoints in the a–b slice of a public MCP registry. Only 40 of them (51.3%) made it through the full flow of initialize → tools/list → one safe tools/call.

    Why it matters: Anonymous health checks on 78 registry MCP servers, with reproducible data on tiered authentication and spec version migration.

  8. Reddit · ClaudeCode / Codex / VibeCoding22

    Claude Code 从多个 API/MCP 工具拉取数据时,如何处理部分失败?

    有开发者提出 Claude Code 工作流中的部分失败问题:当 Claude 调用 5 个数据源、其中 1 个超时并返回不完整数据时,是让 Claude 继续并显式标记缺失来源、重试,还是直接终止任务。他更担心 Claude 拿到看似足够有效的数据后自信完成任务,却没意识到关键信息已缺失,并询问实际工作流中是否有人处理得较好。

    Awaiting translation

  9. DEV Community · MCP62

    A2A 与 MCP 在 2026 年如何分工:什么时候该让智能体互相通信而不是调用工具

    作者认为 MCP 与 A2A 不是竞争关系,而是不同层次的两类协议:MCP 面向被调用的工具与数据服务,A2A 面向拥有目标、能自行规划并回报任务状态的同级智能体。判断标准是问对方是否拥有目标并自行决策,是能力就归 MCP,是自主工作者就归 A2A。两者可以组合成栈,A2A 负责智能体之间的委派,MCP 负责智能体内部调用工具,作者建议先用工具,只有存在真正可委派的目标时才升级为智能体。

    Awaiting translation

  10. Reddit · ClaudeCode / Codex / VibeCoding22

    用 Claude Code 自动投递 LinkedIn 和 Indeed 职位申请

    有用户尝试用 Claude Code 配合 Playwright MCP 在 LinkedIn 和 Indeed 上自动投递职位,但 Claude 拒绝复制粘贴一次性验证码,也无法用已连接的密码应用创建用户名和密码。Playwright MCP 会打开一个未登录的新 Chrome 浏览器,需先手动登录两个平台,Claude 才能读取已收藏职位并逐个申请。

    Awaiting translation

  11. Hacker News · MCP78

    Flash-Agents: an MCP plugin that hands Claude Code's coding tasks to a DeepSeek Flash worker

    Flash-Agents is a Claude Code plugin that delegates bounded coding work—implementing slices, porting tests, reviewing diffs, mapping out a codebase—to a DeepSeek V4.1 Flash worker, while Claude keeps architecture, acceptance criteria, and final review.

    Why it matters: The author outsources Claude Code's coding tasks to a DeepSeek Flash worker and shares the sandbox, patches, and measured data, so you can judge the cost and safety boundaries for yourself.

  12. Reddit · ClaudeCode / Codex / VibeCoding58

    AI Pair 发布 VS Code 扩展:让 AI 智能体以人类节奏打字并讲解

    作者发布 VS Code 扩展 AI Pair Programmer,让编程智能体在编辑器里以可跟上的速度逐字输入并解释自己在做什么,用户可随时打断或接管。该扩展内置支持 Claude Code、Codex、OpenCode、Gemini CLI、Cursor 和 GitHub Copilot,任何支持 MCP 的智能体也可手动接入,作者称它更适合能力较强的模型,弱模型在这种工作方式下容易吃力。

    Awaiting translation

  13. Hacker News · MCP78

    Spill:把超大的 MCP 返回结果移出上下文,存入本地 DuckDB

    Spill 是一个 Apache-2.0 开源工具,通过 Hook 拦截超过 32 KiB 的 MCP 工具返回,将其存为本地 DuckDB 表(~/.spill/spill.duckdb),智能体只拿到一个紧凑描述符,再用 SQL 查询而不是读入 5 万 token 的原始 JSON。

    Awaiting translation

    Why it matters: Spill 把超大 MCP 返回落到本地 DuckDB,让智能体用 SQL 取数,为上下文窗口紧张提供了一种可复用的思路。

  14. 宝玉70

    amontlabs/lcu 把 Codex 的 Computer Use 单独拆出,让 Claude Code、Codex CLI、Pi 等 Agent 工具通过 MCP 调用。

    Awaiting translation

    Quoted向阳乔木@vista8

    发现一个牛逼的东西,让任意 Agent 调用 Codex 的 Computer Use。 Codex 最强的就是 Computer Use。 但最近用 Claude Opus 5.5比较多,这样就强强联合了。 刚测试通过,安装后建议配置个 Hook,指定白名单可控制哪些 App 安装地址见评论区