๐Ÿ”Œ MCP (Model Context Protocol)

An open protocol that standardizes how AI applications (hosts/clients) connect to external tools, resources, and prompts through MCP servers. โ€œUSB-C for AI integrations.โ€

Concepts

  • Architecture: host โ†’ client โ†’ server; JSON-RPC 2.0 messages; capability negotiation
  • Transports: stdio (local) and Streamable HTTP (remote)
  • Server primitives: tools (model-controlled actions), resources (app-controlled context), prompts (user-controlled templates)
  • Client features: sampling, roots, elicitation
  • Auth for remote servers: OAuth 2.1-based authorization
  • Security: tool poisoning, prompt injection via tool output, confused deputy, least privilege, user consent for sensitive tools โญ
  • Ecosystem: official SDKs (TypeScript, Python, Java, Go, Kotlin, C#), MCP Inspector, registries

๐Ÿงช Labs (๐ŸŸข warm-up โ†’ ๐ŸŸก core โ†’ ๐Ÿ”ด hard โ†’ โšซ boss)

  • ๐ŸŸข Run an existing MCP server (filesystem/GitHub) with MCP Inspector
  • ๐ŸŸก Orbit MCP server in Spring AI (tools + resources)
  • ๐Ÿ”ด A read-only Go MCP server (official Go SDK) for run logs/metrics
  • ๐Ÿ”ด Remote HTTP transport with OAuth + per-tool approval
  • โšซ An MCP client in orbit-tools: dynamic tool discovery from external servers with scopes

๐Ÿง  Cognitive tasks

  • Threat model: tool poisoning, a confused deputy, injection via tool output

๐Ÿ›ฐ๏ธ Orbit integration

  • Orbit is usable from Claude Desktop / Claude Code / IDEs as an MCP server

Go deeper

๐Ÿงฉ AI & Agent Patterns ยท ๐Ÿ”’ Security Engineering

Resources

  • modelcontextprotocol.io (spec, docs, quickstarts) โญ ยท SDK repos on GitHub ยท Spring AI MCP docs