A builder audited the human-in-the-loop gate on his own MCP write tool and found a keyword argument the caller sets. Optional evidence makes an optional check.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence62
Three near-identical skills on Claude Code v2.1.263 show that context: fork isolates the conversation and leaves the filesystem alone, because the subagent still holds Read and Bash, at roughly five times the token cost.
Reality
- Evidence68
- Adoption22
- Hype gap+12
- Incentives30
- Confidence62
Once the client-side contract is a URL and a bearer header, nothing in your config records what that key may write. The decision moved to the mint screen, which is the screen easiest to skip.
Reality
- Evidence32
- Adoption20
- Hype gap+15
- Incentives82
- Confidence48
A dev.to essay splits agent architecture into five control layers and shows that only one of four failures in its worked example is fixable by editing instructions.
Reality
- Evidence22
- Adoption
- Insufficient
- Hype gap+34
- Incentives38
- Confidence30
A dev.to argument worth taking literally: if your model reads untrusted text and can act, injection is already live. The only controls that held up sit outside the prompt.
Reality
- Evidence38
- Adoption
- Insufficient
- Hype gap−12
- Incentives55
- Confidence44