Skip to content

MCP and tool calling

Using and building MCP servers, configuring tool calls, and keeping them secure.

Latest curated items

Items 41–59 · 59 total
5/8Fri
  1. Permission Protocol · AI Agent Incident Tracker80

    Claude Code 遭恶意 npm 包经 MCP 中间人劫持窃取 OAuth token

    Mitiga Labs 披露一条针对 Claude Code 的攻击路径:恶意 npm 包通过 postinstall 钩子修改 ~/.claude.json,把 MCP 服务器 URL 替换为攻击者代理,使每次 MCP 会话的 OAuth token 和 SaaS 凭据都经攻击者基础设施转发。

    Awaiting translation

    Why it matters: 披露了恶意 npm 包通过篡改 MCP 配置劫持 OAuth token 的完整攻击链,并指出配置变更缺少授权校验这一根因。

  2. Permission Protocol · AI Agent Incident Tracker82

    Cline AI agent 曝 CVE-2026-44211:未认证 WebSocket 可劫持终端并 RCE

    Cline 的 kanban WebSocket 服务在 localhost 上无认证运行,任意网页可连接 ws://127.0.0.1:3484/api/terminal/io 直接向 Agent 终端 PTY 注入 shell 命令,实现未认证的终端劫持与远程代码执行,CVSS 9.3,影响 v2.13.0 之前所有版本,披露时无补丁。

    Awaiting translation

    Why it matters: CVE-2026-44211 的完整链路与根因拆解,可帮助开发者判断本地 Agent 终端的暴露面。

  3. 宝玉78

    Why the Claude Code team uses HTML instead of Markdown as the agent output format

    Claude Code team member Thariq makes the case for replacing Markdown with HTML as the output format for AI agents: HTML packs in more information, is easier to share, and supports two-way interaction, while Markdown's editing advantage stopped mattering once he switched to making changes through prompts.

    Why it matters: Claude Code team members explain why they use HTML instead of Markdown as the agent output format, and share prompts you can use as-is along with the scenarios they fit.

5/7Thu
  1. Permission Protocol · AI Agent Incident Tracker78

    Microsoft Semantic Kernel 提示词注入漏洞可经 eval() 实现主机级远程代码执行

    Microsoft Security 披露 Semantic Kernel 的两个漏洞 CVE-2026-25592 和 CVE-2026-26030,提示词注入可把 AI 模型输出变成主机级远程代码执行。

    Awaiting translation

    Why it matters: 材料梳理了 Semantic Kernel 两个漏洞的成因与补丁版本,可帮助使用该框架的团队判断自身暴露面。

4/27Mon
  1. Permission Protocol · AI Agent Incident Tracker83

    AI 编程智能体 9 秒删除 PocketOS 生产数据库及备份

    PocketOS 据报在一次 Railway API 调用中丢失生产数据库和卷级备份,整个过程仅 9 秒,人类来不及介入。事故分析指出危险能力不在代码生成,而在于智能体持有具备生产破坏权限的云厂商令牌;仅靠 PR 门禁看不到绕过代码仓库的直接 Railway API 删除,授权检查应前置到删除生产数据或备份的云厂商 API 调用之前,并要求签名回执写明生产环境、资源、动作和签署人。

    Awaiting translation

    Why it matters: 复盘一次智能体凭令牌直接删除生产库与备份的事故,指出授权检查应放在云厂商 API 调用之前。

4/23Thu
  1. Permission Protocol · AI Agent Incident Tracker85

    OpenClaw: Four Chained CVEs Expose 24.5 Public AI Agent Servers

    Four chained CVEs in OpenClaw affect roughly 24.5 publicly exposed AI agent servers, letting attackers steal credentials, escalate to owner-level gateway control, and plant persistent backdoors on the host.

    Why it matters: Mapping the chained exploitation path across these four CVEs and the missing authorization boundaries helps teams running OpenClaw assess their own exposure.

4/10Fri
  1. claude.dev · Anthropic Developer Blog74

    Anthropic 工程师谈 Claude Code 的工具设计:如何像智能体一样思考

    Anthropic 的 Thariq Shihipar 复盘了 Claude Code 工具设计中的取舍,核心主张是工具要贴合模型自身能力,而判断能力边界只能靠观察输出和反复实验。

    Awaiting translation

    Why it matters: Anthropic 工程师复盘 Claude Code 工具设计的取舍,给出可迁移到自建智能体的判断方法。

4/5Sun
  1. Drew Breunig78

    How Claude Code assembles system prompts

    Based on the Claude Code source code that leaked unexpectedly last week, Drew Breunig mapped out how the system prompt is assembled: components fall into two categories—always included and conditionally included—and shift based on toggles like output_style, repl_mode, user_type_ant, skills_enabled, and mcp_connected.

    Why it matters: The author breaks down the dynamic assembly logic behind Claude Code's system prompt, showing how conditional context engineering works in practice.

3/16Mon
  1. 宝玉78

    The 8 Levels of Agent Engineering: From Tab Completion to Autonomous Agent Teams

    Bassim Eledath breaks the practical path of AI-assisted programming into 8 levels, from tab completion and agentic IDEs to context engineering, compound engineering, MCP and Skills, Harness Engineering, background agents, and finally autonomous agent teams.

    Why it matters: The author lays out AI-assisted programming as 8 levels, from tab completion to autonomous agent teams, so readers can figure out where their own team stands.

2/26Thu
2/5Thu
  1. Martin Fowler · Exploring Generative AI75

    Context Engineering for Coding Agents: A Look at Configuration Options, Using Claude Code as an Example

    A Martin Fowler team article breaks down context engineering for coding agents, sorting context configuration into reusable prompts (instructions and guidelines), context interfaces (tools, MCP Servers, Skills), and workspace files. It then splits these by "who decides what gets loaded" into three categories: the LLM, the human, and the agent software.

    Why it matters: Using Claude Code as an example, this piece walks through how to configure context for coding agents and lays out the trade-offs between loading on demand and building up gradually.

2/1Sun
  1. Permission Protocol · AI Agent Incident Tracker88

    Moltbook 硬编码 Supabase 密钥泄露 150 万 agent API token,可被完全劫持

    Wiz 研究人员从 Moltbook 生产环境 Next.js 静态 JS 包中提取出硬编码的 Supabase API key,无需认证即可对生产数据库读写,暴露 150 万 agent API token、3.5 万个邮箱地址和私有消息。

    Awaiting translation

    Why it matters: 复盘了硬编码密钥、缺失 RLS 与无授权边界三层叠加如何让 150 万 agent token 可被任意读取。

1/29Thu
  1. Permission Protocol · AI Agent Incident Tracker80

    OpenClaw 控制 UI 跨站 WebSocket 劫持漏洞可导致远程代码执行

    OpenClaw 的 Web 控制 UI 存在跨站 WebSocket 劫持漏洞 CVE-2026-25253(CVSS 8.8),攻击者诱导受害者访问恶意链接后,可静默窃取 OpenClaw 认证 token,并直连受害者本机 OpenClaw 实例执行任意命令,从而完全控制开发者工作站,获得文件读写与 shell 执行权限。

    Awaiting translation

    Why it matters: 材料完整还原了 OpenClaw 控制 UI 的 CSWSH 漏洞利用链与授权边界缺失,可据此检查同类本地 Agent 工具的 WebSocket 鉴权。

1/11Sun
  1. OpenAI Developer Blog · Codex71

    Skyscanner 如何用 JetBrains MCP 增强 Codex CLI

    Skyscanner 工程师把 OpenAI 的 Codex CLI 接入 JetBrains IDE 的 MCP server,让 Codex 能调用 IDE 的 get_file_problems 检查文件错误、执行预设的 run configurations 跑测试和 lint。

    Awaiting translation

    Why it matters: Skyscanner 工程师把 Codex CLI 接入 JetBrains MCP,让 AI 直接读取 IDE 报错并跑测试,读者可借鉴这套反馈闭环。

1/1Thu
  1. Permission Protocol · AI Agent Incident Tracker76

    Attackers used Claude Code to conduct reconnaissance and password spraying against the OT environment of a Mexican water utility.

    Dragos’ investigation shows that attackers used Claude Code and OpenAI GPT-4.1 to target the OT environment of a Mexican water company. Claude Code handled broad discovery, identifying vNode industrial gateways, researching vendor credentials, generating password lists, and executing password spraying, while GPT-4.1 handled structured data analysis and Spanish-language output.

    Why it matters: Dragos reconstructed the full chain of how attackers used Claude Code and GPT-4.1 to conduct reconnaissance and password spraying against a Mexican water utility’s OT environment, showing how AI was actually divided across the intrusion lifecycle.

10/23Thu
  1. Jesse Vincent69

    Using episodic-memory to give Claude Code cross-session memory

    The author built the episodic-memory plugin for Claude Code so it can search past session logs. By default, Claude Code deletes the .jsonl session logs under ~/.claude/projects after one month; you can extend retention via cleanupPeriodDays in ~/.claude/settings.json.

    Why it matters: The author turned Claude Code's session logs into semantically searchable episodic memory, so readers can judge for themselves how long-term context is preserved across sessions.

10/19Sun
  1. Jesse Vincent71

    The author built a custom superpowers-chrome MCP that cut startup overhead from 13678 tokens to 947.

    The author built a lightweight Chrome MCP and Skill for Claude Code called superpowers-chrome. At startup, the MCP configuration takes up only 947 tokens, while Microsoft's Playwright MCP needs 13678 tokens just to be available—about 7% of the context window.

    Why it matters: The author compares the token overhead of a self-built Chrome MCP against Playwright MCP, laying out the concrete trade-offs involved in designing tool interfaces for LLMs.

10/16Thu
  1. Jesse Vincent78

    Anthropic launches its official Skills system across Claude Code, Claude.ai, and the Claude API

    Anthropic rolled out its first-party Skills system simultaneously on Claude Code, Claude.ai, and the Claude API, and author Jesse Vincent quickly followed with a new version of Superpowers built on the official Skills.

    Why it matters: Drawing on nearly a month of hands-on use, the author compares the official Skills with his own setup and lays out the trade-offs involved in migrating.

9/24Wed
  1. Hacker News · Context Engineering 讨论87

    Manus's AI Agent Context Engineering Experience: Six Practical Principles

    The Manus team shares context engineering lessons from building AI agents, centered on designing around the KV cache, managing tools by masking rather than removing them, treating the file system as context, steering attention by restating to-do items, keeping errors in context, and avoiding getting stuck on few-shot examples.

    Why it matters: The Manus team distilled lessons from rewriting their agent framework four times into six context engineering principles—ready to apply directly to your own agent implementation.