๐ MCP (Model Context Protocol)
An open protocol that standardizes how AI applications (hosts/clients) connect to external tools, resources, and prompts through MCP servers. โUSB-C for AI integrations.โ
Concepts
- Architecture: host โ client โ server; JSON-RPC 2.0 messages; capability negotiation
- Transports: stdio (local) and Streamable HTTP (remote)
- Server primitives: tools (model-controlled actions), resources (app-controlled context), prompts (user-controlled templates)
- Client features: sampling, roots, elicitation
- Auth for remote servers: OAuth 2.1-based authorization
- Security: tool poisoning, prompt injection via tool output, confused deputy, least privilege, user consent for sensitive tools โญ
- Ecosystem: official SDKs (TypeScript, Python, Java, Go, Kotlin, C#), MCP Inspector, registries
๐งช Labs (๐ข warm-up โ ๐ก core โ ๐ด hard โ โซ boss)
- ๐ข Run an existing MCP server (filesystem/GitHub) with MCP Inspector
- ๐ก Orbit MCP server in Spring AI (tools + resources)
- ๐ด A read-only Go MCP server (official Go SDK) for run logs/metrics
- ๐ด Remote HTTP transport with OAuth + per-tool approval
- โซ An MCP client in orbit-tools: dynamic tool discovery from external servers with scopes
๐ง Cognitive tasks
- Threat model: tool poisoning, a confused deputy, injection via tool output
๐ฐ๏ธ Orbit integration
- Orbit is usable from Claude Desktop / Claude Code / IDEs as an MCP server
Go deeper
๐งฉ AI & Agent Patterns ยท ๐ Security Engineering
Resources
- modelcontextprotocol.io (spec, docs, quickstarts) โญ ยท SDK repos on GitHub ยท Spring AI MCP docs