Skip to content

standard

Model Context Protocol

Open standard for connecting AI models and agents to external tools, data sources, and resource servers, enabling standardized tool-calling across clients.

Known aliases

  • MCP
  • MCP 2.0
  • MCP 2025-11-25
  • MCP 2026-07-28
  • MCP 2.x SDK
  • MCP gateway
  • .mcp.json
  • mcp.json
  • MCP server
  • mcpServers
  • MCP servers
  • MCP spec 2026-07-28
  • MCP specification
  • MCP stdio
  • MCP tools specification
  • stable 2026-07-28 MCP specification
  • Streamable HTTP MCP
  • Warp Factories MCP

Relationships

No evidence-backed relationships are recorded.

Current stories

product6 publishers

Reco takes $55 million into an agent security market where two dozen vendors sound alike

Reco, whose software maps what AI agents can reach and cuts unneeded access, added $55 million in a field of at least two dozen rivals. Their pitches share one vocabulary, so a buyer has to compare what each product does once it finds an agent.

Perspective Coverage

6 publishers
Builder
Builder 24%
Operator
Operator 36%
Investor
Investor 40%

Reality

Evidence55
Adoption40
Hype gap+30
Incentives70
Confidence60
build2 publishers

Two-thirds of failed agent runs in ThinkingBox exited cleanly with the backend still wrong

Microsoft and Hugging Face's ThinkingBox found that 67.24% of 79,853 failed agent runs ended cleanly, with no final tool error. Those failures showed up only when executable checks read the records each run left in the backend.

Perspective Coverage

3 publishers
Builder
Builder 52%
Operator
Operator 38%
Investor
Investor 10%

Reality

Evidence60
Adoption
Insufficient
Hype gap+10
Incentives35
Confidence68
build5 publishers

Claude Code mods let unsandboxed plugin code answer the agent's permission requests

Anthropic's Claude Code mods, on by default from 2.1.287, let JavaScript or TypeScript code rewrite prompts, block tool calls and approve permission requests. For teams, the governance question moves from what the agent is told to which code it runs.

Perspective Coverage

5 publishers
Builder
Builder 59%
Operator
Operator 36%
Investor
Investor 5%

Reality

Evidence78
Adoption15
Hype gap+15
Incentives60
Confidence72
build1 publisher

One COPY line runs a shell despite AWS's read-only Postgres MCP filter

AWS published CVE-2026-87911, a CVSS 9.6 command injection in its own postgres-mcp-server, where one COPY ... TO PROGRAM line runs a shell on the host. The read-only promise lives in a regex filter that lets the COPY keyword through.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap+25
Incentives40
Confidence50
invest4 publishers

Andreessen Horowitz puts $38 million behind doxx.net's server-free networks for AI agents

Andreessen Horowitz led a $38 million Series A for doxx.net, a Miami startup building private networks for AI agents. The cash funds an open beta resting on one disclosed metric, the company's own count of more than 38 million potential threats blocked.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 25%
Investor
Investor 41%

Reality

Evidence55
Adoption10
Hype gap+45
Incentives75
Confidence60
build3 publishers

Cloudflare opens a closed beta that bills AI agents per request over HTTP 402

Cloudflare put its Monetization Gateway into closed beta, letting domain owners charge AI agents per request via HTTP 402, with four use cases in production. Cloudflare scopes it to APIs, tools and data, where each request is a single use.

Perspective Coverage

3 publishers
Builder
Builder 58%
Operator
Operator 22%
Investor
Investor 20%

Reality

Evidence60
Adoption20
Hype gap+20
Incentives70
Confidence60
build1 publisher

NVIDIA's Sentry enforces agent limits from a separate BlueField-4 card

NVIDIA's Open Agent Safety Platform runs Sentry, a watchdog on separate BlueField-4 cards that isolates an agent within milliseconds of crossing its boundary. For teams running coding agents, the design takes enforcement out of the agent's own process, where prompts and permission lists sit today.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence50

Earlier coverage

  1. Teams leaving Agent Builder must decide whether OpenAI or their own code runs the agent loop

    Build · October 2, 2026 · 1 publisher

  2. Pi 1.0 runs MCP tools inside a sandbox so their output stays out of context

    Build · October 2, 2026 · 1 publisher

  3. Aweb's durable agent mail reaches Claude Code only with permission prompts turned off

    Build · October 2, 2026 · 1 publisher

  4. Live MCP servers trail the stateless 2026-07-28 revision that clients already ship

    Build · October 1, 2026 · 1 publisher

  5. DoorDash moves checkout into Apple Messages for 20,000 pilot users

    Leadership · September 30, 2026 · 2 publishers

  6. Google's pkg.go.dev API reaches v1 with eight JSON endpoints aimed at coding agents

    Build · October 1, 2026 · 1 publisher

  7. Two MCP Python SDK OAuth providers stay exposed after upgrade until code names an issuer

    Security · September 29, 2026 · 2 publishers

  8. DoorDash wraps MCP tool calls in one gateway for permissions, credentials and audit

    Build · September 30, 2026 · 1 publisher

  9. Pi adds MCP through a JavaScript sandbox that skips tool-schema preloading

    Build · September 30, 2026 · 1 publisher

  10. Fed builds a rule book for the AI agents that now make half of FRED's visits

    Invest · October 1, 2026 · 1 publisher

  11. MCP's September 28 release lets any server behind a load balancer answer any request

    Build · October 1, 2026 · 1 publisher

  12. Exabeam's Nova agent now runs its own follow-up searches during security incidents

    Product · October 1, 2026 · 1 publisher

  13. Chrome switches to two-week releases from version 153 on desktop, Android and iOS

    Build · October 1, 2026 · 1 publisher

  14. Microsoft 365 Copilot now draws business context from Fabric IQ by default

    Build · September 30, 2026 · 2 publishers

  15. Call4me puts Claude Code and Codex on the phone with businesses at $0.25 a minute

    Build · October 1, 2026 · 1 publisher

  16. COMMIT; DROP TABLE slips past the reference Postgres MCP server's read-only guard

    Build · September 30, 2026 · 1 publisher

  17. Blueprint Alliance coalition aims to build agentic AI security standards around four key questions, lists six identity principles as governance guidance

    Security · September 30, 2026 · 1 publisher

  18. Kong AI Gateway hides the rollback tool from Muse Code's investigator by filtering tools/list per identity

    Build · September 30, 2026 · 1 publisher

  19. Robinhood picks its own Bitstamp over Lighter for US crypto perpetuals

    Invest · September 30, 2026 · 11 publishers

  20. A low-privilege LiteLLM key could run system commands through its MCP test endpoints

    Build · September 30, 2026 · 1 publisher

  21. n8n's preview Agents call existing workflows as tools for open-ended jobs like triage

    Build · September 30, 2026 · 1 publisher

  22. OpenAI took 84 days to report an agent that pushed past Medicare portal refusals

    Build · September 30, 2026 · 1 publisher

  23. OpenAI's Agents API beta hosts the agent loop that teams used to write themselves

    Build · September 29, 2026 · 1 publisher

  24. MCP servers that answer expired sessions with 401 push OAuth clients into needless re-logins

    Build · September 29, 2026 · 1 publisher

  25. Fingerprint's new tools separate verified AI agents from spoofed automation

    Product · September 29, 2026 · 1 publisher

  26. OpenAI opens the plugin system behind ChatGPT's own features to outside developers

    Build · September 29, 2026 · 1 publisher

  27. Omnissa pitches Elara at the unapproved AI assistants employees run on work devices

    Product · September 29, 2026 · 1 publisher

  28. CData's gateway holds AI agents to each user's own row and column permissions

    Product · September 29, 2026 · 1 publisher

  29. ProvenanceGuard flags MCP agent answers that credit a true fact to the wrong tool

    Build · September 29, 2026 · 1 publisher

  30. Komprise wants AI agents to reach every enterprise file store through one MCP server

    Product · September 29, 2026 · 1 publisher

  31. env zero lets platform teams decide how much infrastructure drift its agents fix alone

    Product · September 29, 2026 · 1 publisher

  32. SaaStr puts Salesforce's agent API meter at 60 to 1,200 times its integration rate

    Invest · September 28, 2026 · 1 publisher

  33. Timescale's agent-run memory sprint turned on a human checking what each metric counted

    Product · September 28, 2026 · 1 publisher

  34. Stacklok's Mecatl trades the coding agent's unrestricted shell for a governed tool catalog

    Product · September 28, 2026 · 1 publisher

  35. Ox Security finds nearly 16% of public MCP server hostnames resolve outside the US

    Security · September 28, 2026 · 1 publisher

  36. Open-source Authorizer checks user permissions before AI search ranks company files

    Security · September 28, 2026 · 1 publisher

  37. A custom-domain token let a Cursor agent wipe PocketOS's production database and backups

    Build · September 28, 2026 · 1 publisher

  38. Coding agents are writing API keys into plain-text memory, Vectorize CEO says

    Security · September 28, 2026 · 1 publisher

  39. Claude Code's .mcp.json expansion passes bare $VAR and unset ${VAR} to servers as raw text

    Build · September 27, 2026 · 1 publisher

  40. One MCP server needs a generated config file for every desktop client it serves

    Build · September 27, 2026 · 1 publisher