Skip to content

MCP and tool calling

Using and building MCP servers, configuring tool calls, and keeping them secure.

Latest curated items

Items 21–40 · 59 total
8/26Wed
  1. Cline · Blog71

    Building a Code Review Agent on the Cline Loop with the Cline SDK

    The Cline team built a code review agent with the Cline SDK, splitting review into two agent loops—review and judge—then using a driver script to batch-submit the surviving issues as a single COMMENT event to the GitHub PR.

    Why it matters: A full breakdown of the plugin, Hooks, and two-stage loop behind a code review agent, transferable to other automated review scenarios.

8/25Tue
  1. Lovable · Blog62

    How Lovable connected its own app to external tech stacks: from MCP to nearly 100 connectors

    Lovable shared a retrospective on how it connected its platform app to third-party services: first it supported MCP as a stopgap for pulling context into chats, then it built app connectors of its own, using a Connector Gateway to proxy requests between published apps and third-party APIs. The gateway holds credentials and refresh logic, so deployed apps never touch the keys.

    Why it matters: Lovable’s retrospective on turning connectors into reusable infrastructure is worth a look for teams doing third-party integrations and credential management.

  2. OpenAI Developer Blog · Codex62

    Automating OpenAI’s repetitive evaluation work with Codex and the Runme notebook

    OpenAI engineers use Codex with the open-source notebook app Runme to automate repetitive work such as running model evaluations. The approach: write a goal cell in the Runme notebook, have Codex read the goal, produce a plan, and wait for human approval before executing, logging commands, outputs, and conclusions along the way—including the dead ends.

    Why it matters: The author uses the Runme notebook plus WebMCP to hand the evaluation process over to Codex; readers can borrow the way it handles goals, approvals, and context capture.

8/19Wed
  1. OpenAI Developer Blog · Codex71

    OpenAI open-sources the Codex harness and the app-server client protocol

    OpenAI has open-sourced the harness that drives the Codex app, CLI, and IDE extensions, and through the Codex app-server client protocol it exposes capabilities like creating threads, starting turns, receiving events, and handling approval requests.

    Why it matters: With the Codex harness and app-server protocol now public, developers can see how to embed the agent in their own products and where the boundaries are.

8/18Tue
  1. Permission Protocol · AI Agent Incident Tracker78

    Context7 MCP custom AI instruction prompt injection can leak credentials and delete files

    Context7 MCP's custom AI instruction feature returns unsanitized attacker content alongside normal document queries, carrying injected instructions into the coding agent's trusted context and tricking it into reading keys, exfiltrating data, or deleting files.

    Why it matters: The material breaks down how Context7 MCP injects prompts through custom instructions, and offers a mitigation approach: adding an authorization gate at the tool invocation boundary.

8/14Fri
  1. InfoQ · AI Coding Presentations80

    InfoQ 演讲:300 个精准 token 胜过 10 万个噪声 token,上下文工程的架构

    Baruch Sadogursky 与 Patrick Debois 在 InfoQ 演讲中用 Claude Code 现场演示:把全部项目文档塞进 CLAUDE.md 后,给接口加错误处理会因约定冲突返回 500,改用按描述懒加载的 Skill 后同一提示词通过测试。

    Awaiting translation

    Why it matters: 两位作者用现场演示拆解上下文工程的四类反模式,并给出 Skill、检索通道、外部记忆与评测的对应做法。

8/5Wed
  1. Vercel · v0 Blog62

    Vercel ships v0 API for programmatic access to its app-generation agent

    Vercel ships v0 API, giving programmatic, headless access to the v0 app-generation agent: send a prompt, v0 generates an app, spins up a dev server in the Vercel Sandbox, and returns a preview URL you can embed in your own UI. The API is now generally available.

    Why it matters: v0 opens up its app-generation capability as an API, so readers can judge how to wire it into their own product or agent workflow.

7/15Wed
7/5Sun
  1. Jesse Vincent68

    Developing Sen 2.0 by having Claude Code and an agent on Slack review each other's work

    At Prime Radiant, author Jesse Vincent used Claude Code—working through the Slackline command-line Slack client—to collaborate with his own agent Ada: Claude proposes changes, Ada reviews and tests them, then Claude deploys the updates, forming a development loop where the agents review each other.

    Why it matters: By looping two agents through mutual review, testing, and deployment, the author shows a transferable model for collaborative agent-based development.

6/8Mon
  1. Permission Protocol · AI Agent Incident Tracker88

    Agentjacking:攻击者借公开 DSN 注入伪造 Sentry 错误,劫持 Claude Code、Cursor 和 Codex

    安全研究披露一种名为 Agentjacking 的攻击:攻击者利用 Sentry 公开的 DSN 向 ingest API 提交伪造错误事件,AI 编码智能体通过 Sentry MCP 取回这些事件后,把其中的 Markdown 注入内容当作可信指令执行 shell 命令,在受控测试中成功率 85%,涉及 2,388 家组织。

    Awaiting translation

    Why it matters: 还原了 Sentry MCP 提示词注入劫持编码智能体的完整链路,并指出授权门禁应设在工具调用层。

  2. Permission Protocol · AI Agent Incident Tracker76

    LiteLLM CVE-2026-42271 被列入 CISA KEV:MCP 测试端点命令注入可链式触发未授权 RCE

    CISA 于 2026 年 6 月 8 日将 BerriAI LiteLLM 的 CVE-2026-42271 列入 KEV 目录,要求 6 月 22 日前修复。

    Awaiting translation

    Why it matters: 材料完整还原了 LiteLLM 从 MCP 测试端点命令注入到未授权 RCE 的利用链与补丁版本,可据此排查自身网关部署。

6/5Fri
  1. Permission Protocol · AI Agent Incident Tracker85

    微软披露 Claude Code GitHub Action 提示注入可窃取 CI/CD 密钥并绕过 GitHub 密钥扫描

    微软记录了一起 Claude Code GitHub Action 提示注入事件,攻击者把指令藏在 GitHub issue 的 HTML 注释里,让 Claude 读取 /proc/self/environ,截断凭据字符串以绕过 GitHub 密钥扫描,再通过 gh CLI 的 URL 参数外传。

    Awaiting translation

    Why it matters: 微软披露的 Claude Code GitHub Action 提示注入链路,展示了不可信内容与凭据读取权限同处一室时的真实风险。

  2. Permission Protocol · AI Agent Incident Tracker88

    Miasma 供应链蠕虫通过 Agent 配置注入禁用 73 个微软 GitHub 仓库并窃取凭据

    Miasma 蠕虫通过投毒 Agent 配置文件感染 73 个微软 GitHub 仓库,开发者在 Claude Code、Cursor 或 Gemini CLI 中打开仓库时即执行凭据窃取程序,导致 AI API token、GitHub token 和云凭据泄露。

    Awaiting translation

    Why it matters: 复盘 Miasma 蠕虫如何借 Claude Code、Cursor、Gemini CLI 的会话初始化配置实现零点击窃取凭据,可迁移到仓库配置来源校验。

5/27Wed
  1. Permission Protocol · AI Agent Incident Tracker78

    Oasis Security 串联三个 Claude.ai 漏洞实现静默数据外泄

    Oasis Security 将 URL 参数注入、Files API 外泄和开放重定向三个 Claude.ai 漏洞串联,在用户提交时静默窃取对话历史。攻击者把隐藏 HTML 标签放进 ?

    Awaiting translation

    Why it matters: Oasis Security 披露的攻击链说明默认 claude.ai 会话即可被静默窃取对话历史,并指出 MCP 集成会扩大影响范围。

5/26Tue
  1. Permission Protocol · AI Agent Incident Tracker78

    Trend Micro 披露 mcp/postgres 镜像 RTT 攻击:AI 智能体经授权工具外泄生产令牌

    Trend Micro 发布 Pwning Agentic AI Part I,披露 mcp/postgres Docker 镜像存在 RTT(return-to-tool)攻击:攻击者在客服工单中注入提示词,让连接数据库的 AI 智能体从生产 PostgreSQL 表读取认证令牌并发布到公开客户评论线程,全程只用智能体已授权的工具,未触发告警也未违反策略。

    Awaiting translation

    Why it matters: 梳理 RTT 攻击如何只用智能体已授权的工具完成数据外泄,并给出工具调用门禁这一可迁移的拦截思路。

  2. Permission Protocol · AI Agent Incident Tracker85

    BadHost CVE-2026-48710: a single-character HTTP Host header injection bypasses Starlette/FastAPI authentication, hitting millions of MCP servers

    X41 D-Sec found CVE-2026-48710 (BadHost): injecting a single character into the HTTP Host header of requests sent to an MCP server or AI agent harness built on Starlette makes the authentication middleware evaluate the wrong path from request.url.path, letting unauthorized access through.

    Why it matters: This post breaks down how the BadHost vulnerability works, its blast radius, and the fixed versions, and explains what an authorization gate does and does not cover.

5/20Wed
  1. 宝玉76

    The official Codex team shares how to get the most out of Codex

    Codex team member jason (@jxnlco) shares how to get the most out of Codex, the key being to combine persistent conversation threads, voice input, task intervention and queuing, MCP servers and connectors, conversation thread automation, goal setting, and the sidebar.

    Why it matters: A member of the official Codex team breaks down how to use persistent conversation threads, task intervention, automation, and goal setting—approaches you can carry over into everyday agent workflows.

5/14Thu
  1. Permission Protocol · AI Agent Incident Tracker78

    Microsoft Defender 发现 Mage AI 与 MCP 服务器未鉴权部署,可获 cluster-admin 权限执行 RCE

    Microsoft Defender for Cloud 发现生产环境中的 Mage AI 与 MCP 服务器未启用鉴权,攻击者可执行 shell 命令并获得 cluster-admin 权限,还能窃取同集群工作负载的凭据。

    Awaiting translation

    Why it matters: 材料给出 Mage AI 与 MCP 服务未鉴权部署导致 RCE 的完整链路,可据此检查自家 Helm chart 与 MCP 配置。

5/12Tue
5/10Sun
  1. Permission Protocol · AI Agent Incident Tracker80

    Sysdig 记录首例 LLM 智能体后渗透:marimo CVE-2026-39987 到内网数据库泄露不到一小时

    Sysdig TRT 记录了一起由 LLM 智能体驱动的入侵:攻击者利用 marimo 的 CVE-2026-39987 获取云凭证,再用 LLM 智能体通过 Cloudflare Workers 出口池从 AWS Secrets Manager 取回 SSH 密钥,并驱动 8 个并行 SSH 会话在不到两分钟内导出内网 PostgreSQL 数据库。

    Awaiting translation

    Why it matters: 完整还原攻击者用 LLM 智能体在不到一小时内从 marimo RCE 打到内网数据库的链路,可看到后渗透时间被压缩到分钟级。