<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>MCPProxy Blog</title><description>MCP security research, tool discovery deep dives, and AI-agent infrastructure engineering notes from the MCPProxy team.</description><link>https://mcpproxy.app/</link><language>en-us</language><item><title>MCPProxy v0.70.0: Profiles, Per-Client Credentials, and Agents That Find Their Tools</title><link>https://mcpproxy.app/blog/2026-10-04-mcpproxy-v0-70-0-profiles-and-agents-that-find-their-tools/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-10-04-mcpproxy-v0-70-0-profiles-and-agents-that-find-their-tools/</guid><description>v0.70.0 adds profiles with per-tool policy, gives every connected client its own scoped credential, reworks navigation around one needs-attention list, and tells agents which servers they can reach, so they stop reaching for gh and curl.</description><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>MCPProxy v0.61.0: Reconnect Storms, Scans That Actually Run, and 47 UX Fixes</title><link>https://mcpproxy.app/blog/2026-08-26-mcpproxy-v0-61-0-reconnect-storms-and-scans-that-run/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-08-26-mcpproxy-v0-61-0-reconnect-storms-and-scans-that-run/</guid><description>v0.61.0 stops the proxy from re-dialing dead upstreams ~9,000 times a day, makes the free security scan run on every new server instead of almost never, masks secrets in the Web UI, and closes 47 findings from two UX audits.</description><pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Three Independent Bodies, One Architecture: The 2026 Convergence on Admission Control for Agentic AI</title><link>https://mcpproxy.app/blog/2026-05-10-three-independent-bodies-converge-on-admission-control/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-05-10-three-independent-bodies-converge-on-admission-control/</guid><description>In the first four months of 2026, three independent security bodies — Forrester, OWASP, and Singapore&apos;s IMDA — each published a major framework for agentic AI security. None coordinated. None cite each other. All three converged on the same architectural requirement at the MCP protocol layer: a default-deny admission control gate.</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Nine Seconds: What a Production Wipe Proves About AI Agent Safety</title><link>https://mcpproxy.app/blog/2026-05-10-nine-seconds-production-wipe-admission-gate/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-05-10-nine-seconds-production-wipe-admission-gate/</guid><description>A Cursor + Claude Opus 4.6 agent wiped PocketOS production in nine seconds on May 9, 2026. Backups were on the same volume. Railway had evals. The evals didn&apos;t help. The missing layer was an admission gate, not better evals.</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>CSAI Is Now Issuing CVEs for MCP Servers: What That Means for Your Admission Records</title><link>https://mcpproxy.app/blog/2026-05-05-csai-mcp-cve-numbering-authority/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-05-05-csai-mcp-cve-numbering-authority/</guid><description>The Cloud Security Alliance&apos;s CSAI Foundation registered as a CVE Numbering Authority in April 2026 — the first AI-specific CNA in the ecosystem, with explicit scope over MCP server vulnerabilities. Every CSAI CVE is a re-review event waiting for an admission record to match against.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Datadog Named Agent Sprawl. MCPProxy Is the MCP Fleet Inventory That Keeps It Traceable.</title><link>https://mcpproxy.app/blog/2026-05-05-datadog-agent-sprawl-fleet-inventory/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-05-05-datadog-agent-sprawl-fleet-inventory/</guid><description>Datadog&apos;s State of AI Engineering 2026 named the consequence of running multiple models in production: agent sprawl. Their prescribed remedy is fleet inventory tracking. At the MCP layer, that inventory has to be created at admission — not retroactively from telemetry.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>85.6% of Your Deployed Agents Don&apos;t Have Full IT Approval: The Gravitee Numbers Behind the MCPProxy Case</title><link>https://mcpproxy.app/blog/2026-05-05-gravitee-85-percent-it-approval-gap/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-05-05-gravitee-85-percent-it-approval-gap/</guid><description>Gravitee&apos;s State of AI Agent Security 2026 quantified the Shadow MCP problem with a single number: only 14.4% of organizations have full IT approval for their agent fleet. The remaining 85.6% is the deployment surface MCPProxy is built to address.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>One Endpoint, Every Client: Running 10 MCP Servers Without Losing Your Mind</title><link>https://mcpproxy.app/blog/2026-04-28-one-endpoint-every-client/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-04-28-one-endpoint-every-client/</guid><description>Claude Desktop, Claude Code, Cursor, Codex CLI, Gemini CLI — five clients, one MCP config to maintain. A three-minute walkthrough of mcpproxy upstream import and a single localhost:8080/mcp endpoint that replaces them all.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>How I Cut My AI Agent&apos;s Tool Context by 97%</title><link>https://mcpproxy.app/blog/2026-04-24-cut-agent-tool-context-97-percent/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-04-24-cut-agent-tool-context-97-percent/</guid><description>A measured before/after: 54,707 tokens of MCP tool definitions shrunk to 818 tokens using a single retrieve_tools meta-tool. The configs, the methodology, and the honest caveats.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Anthropic Said It&apos;s &apos;Expected Behavior.&apos; Here&apos;s the Security Layer That Fixes It Anyway.</title><link>https://mcpproxy.app/blog/2026-04-20-anthropic-expected-behavior-security-layer/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-04-20-anthropic-expected-behavior-security-layer/</guid><description>OX Security found that Anthropic&apos;s MCP STDIO transport lets anyone execute arbitrary OS commands. Anthropic called it expected behavior. Ten CVEs later, somebody has to provide the security defaults the protocol won&apos;t.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>The Attack That Gets Better as Your AI Gets Smarter</title><link>https://mcpproxy.app/blog/2026-04-20-attack-gets-better-ai-gets-smarter/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-04-20-attack-gets-better-ai-gets-smarter/</guid><description>Unit 42&apos;s MCPTox benchmark found 72.8% attack success on o1-mini. More capable models are more vulnerable to MCP sampling injection because the attack exploits instruction-following. You cannot model-upgrade your way out of this.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>The First MCP Vulnerability That Hacks Your Laptop (Not the Server)</title><link>https://mcpproxy.app/blog/2026-04-19-mcp-remote-client-rce/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-04-19-mcp-remote-client-rce/</guid><description>Every previous MCP CVE ran on the server. mcp-remote CVSS 9.6 runs on your laptop — and it fires before you make a single tool call.</description><pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>The 2026 Agent Security Stack: Identity, Admission, and Execution</title><link>https://mcpproxy.app/blog/2026-04-19-agent-security-stack-2026/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-04-19-agent-security-stack-2026/</guid><description>Three independent vendors are building three layers of the agent security stack. Ledger for identity. MCPProxy for admission. NemoClaw for execution. Nobody has named the full stack until now.</description><pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>MCP Is Getting Bidirectional. Here&apos;s Why That Breaks Trust Boundaries.</title><link>https://mcpproxy.app/blog/2026-04-17-mcp-bidirectional-trust-boundaries/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-04-17-mcp-bidirectional-trust-boundaries/</guid><description>SEP-2571 proposes write operations in MCP for the first time. When clients can create resources on servers, cross-client contamination becomes a protocol-level attack surface.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>The Four Layers of MCP Security: Why Scanners, Middleware, Quarantine, and Reputation All Exist</title><link>https://mcpproxy.app/blog/2026-04-13-four-layers-mcp-security/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-04-13-four-layers-mcp-security/</guid><description>A comparison article this week reviewed three MCP security tools. It missed the two layers that matter most. Here is the full four-layer stack — and why the order you deploy them matters.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>The agents.txt Draft Just Expired. Here&apos;s Why It Doesn&apos;t Matter If You&apos;re Running MCPProxy.</title><link>https://mcpproxy.app/blog/2026-04-10-agents-txt-expired/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-04-10-agents-txt-expired/</guid><description>draft-srijal-agents-policy-00 expired today with no working group adoption and 11 competing drafts still fighting for relevance. Here&apos;s why MCPProxy&apos;s security posture is unaffected by any of it.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>CVSS 9.1: Microsoft&apos;s Azure MCP Server CVE Is the Enterprise Wake-Up Call for Gateway Adoption</title><link>https://mcpproxy.app/blog/2026-04-07-cvss-91-azure-mcp-server-cve-enterprise-wake-up-call/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-04-07-cvss-91-azure-mcp-server-cve-enterprise-wake-up-call/</guid><description>CVE-2026-32211 proves that even Microsoft ships MCP servers with missing authentication. Nine confirmed MCP CVEs in one quarter demand a quarantine-first architecture.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Three Sandboxes, Three Problems: Cloudflare, Anthropic, and MCPProxy</title><link>https://mcpproxy.app/blog/2026-03-31-three-sandboxes-ai-isolation/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-31-three-sandboxes-ai-isolation/</guid><description>Cloudflare chose V8 isolates, Anthropic chose OS-native primitives, MCPProxy chose Docker containers. All three are correct — for different threat models. Here is the design space.</description><pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>The MCP Spec Is Converging on MCPProxy&apos;s Architecture</title><link>https://mcpproxy.app/blog/2026-03-27-mcp-spec-converging-mcpproxy-architecture/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-27-mcp-spec-converging-mcpproxy-architecture/</guid><description>MCP specification discussions on gateway authorization, tool integrity, and quarantine patterns are converging toward the architecture MCPProxy has been shipping since day one.</description><pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>MCPwned: What the RSAC Azure RCE Demo Means for Everyone Running MCP</title><link>https://mcpproxy.app/blog/2026-03-27-mcpwned-rsac-azure-rce/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-27-mcpwned-rsac-azure-rce/</guid><description>Token Security&apos;s MCPwned presentation at RSAC 2026 demonstrated CVSS 9.8 RCE in Azure MCP Server. The attack chain exploits MCP&apos;s trust-by-default model. Here is what it means and how to defend.</description><pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Cisco DefenseClaw vs MCPProxy: Two Architectures for Securing MCP Agents</title><link>https://mcpproxy.app/blog/2026-03-25-cisco-defenseclaw-vs-mcpproxy/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-25-cisco-defenseclaw-vs-mcpproxy/</guid><description>Cisco&apos;s DefenseClaw and MCPProxy take fundamentally different approaches to MCP security. Here is an honest comparison of architectures, trade-offs, and when to use each.</description><pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>The First Malicious MCP Server Exfiltrated Data for Weeks</title><link>https://mcpproxy.app/blog/2026-03-24-first-malicious-mcp-server-exfiltration/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-24-first-malicious-mcp-server-exfiltration/</guid><description>The postmark-mcp npm package secretly BCC&apos;d every outgoing email to attackers for weeks. MCPwned demonstrated CVSS 9.8 Azure RCE. Both share the same root cause: MCP servers run trusted by default.</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Why You Cannot Patch Your Way to MCP Security</title><link>https://mcpproxy.app/blog/2026-03-24-cant-patch-mcp-security-architecture/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-24-cant-patch-mcp-security-architecture/</guid><description>Netskope told RSAC 2026: MCP vulnerabilities are architectural. Only 20% get remediated vs 70% for traditional APIs. Patches don&apos;t reach protocol-level attack surfaces. Architecture does.</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>CVE-2026-23744: Your MCP Discovery Pipeline Is an Attack Surface</title><link>https://mcpproxy.app/blog/2026-03-23-cve-2026-23744-discovery-pipeline/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-23-cve-2026-23744-discovery-pipeline/</guid><description>A crafted HTTP request to MCPJam Inspector triggers installation of a malicious MCP server and full RCE. The attack surface is not your tools — it is the mechanism by which you find and install tools.</description><pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Google Cloud Just Made MCP Default — Here Is What You Need</title><link>https://mcpproxy.app/blog/2026-03-23-google-cloud-mcp-default-governance/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-23-google-cloud-mcp-default-governance/</guid><description>Google Cloud enabled fully-managed remote MCP servers across ALL services by default. Every Google Cloud customer now needs to answer: who governs your AI agents&apos; access to production infrastructure?</description><pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>The Three Gates of AI Infrastructure: Why MCP Needs Its Own Gateway Layer</title><link>https://mcpproxy.app/blog/2026-03-22-three-gates-ai-infrastructure/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-22-three-gates-ai-infrastructure/</guid><description>Traefik&apos;s Triple Gate architecture makes it explicit: API gateways, AI gateways, and MCP gateways are three distinct infrastructure layers. Here is why MCP needs its own gateway and how MCPProxy fits.</description><pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>The MCP Gateway Market Just Split in Two — And That Is Good for Open Source</title><link>https://mcpproxy.app/blog/2026-03-21-mcp-gateway-market-split/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-21-mcp-gateway-market-split/</guid><description>The MCP gateway market has visibly split into enterprise commercial platforms and open-source builder tools. This is the same pattern that shaped the API gateway market — and open source won there too.</description><pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>MCP Is Now Permanent Infrastructure: What the Linux Foundation Means for Gateways</title><link>https://mcpproxy.app/blog/2026-03-21-mcp-linux-foundation-gateways/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-21-mcp-linux-foundation-gateways/</guid><description>Anthropic donated MCP to the Linux Foundation&apos;s Agentic AI Foundation, co-founded with Block and OpenAI. MCP gateways just moved from developer tool to mandatory enterprise infrastructure.</description><pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>If Meta&apos;s AI Safety Chief Can&apos;t Stop Her Agent, What Chance Do You Have Without a Gateway?</title><link>https://mcpproxy.app/blog/2026-03-21-meta-ai-safety-agent-gateway/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-21-meta-ai-safety-agent-gateway/</guid><description>Meta&apos;s Director of Alignment watched her AI agent delete hundreds of emails despite explicit instructions. Combine this with 88% of orgs reporting AI agent incidents. Gateway-level controls are no longer optional.</description><pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>MCPwned: Why Your MCP Server Config Is Now an Attack Vector</title><link>https://mcpproxy.app/blog/2026-03-21-mcpwned-config-attack-vector/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-21-mcpwned-config-attack-vector/</guid><description>Check Point&apos;s MCPwned RCE via .claude/settings.json, Azure MCP SSRF CVE-2026-26118, and 30+ CVEs reveal a new attack class: configuration-as-code-execution. Here is how gateways defend against it.</description><pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Gartner Says Deploy MCP Proxies — Here Is What We Built and What We Learned</title><link>https://mcpproxy.app/blog/2026-03-20-gartner-mcp-proxies-what-we-built/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-20-gartner-mcp-proxies-what-we-built/</guid><description>Gartner now recommends MCP gateways for enterprise AI agent deployments. Here is how the landscape looks, what MCPProxy brings, and what is still missing across the entire category.</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>The MCP Breach Timeline: What 10 Months of Vulnerabilities Teach Us</title><link>https://mcpproxy.app/blog/2026-03-20-mcp-breach-timeline-lessons/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-20-mcp-breach-timeline-lessons/</guid><description>AuthZed&apos;s MCP breach timeline documents recurring vulnerability patterns from April to December 2025. Every pattern maps to defenses MCPProxy already ships.</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>CVE-2026-27896: How Go&apos;s JSON Parsing Nearly Broke MCP Security</title><link>https://mcpproxy.app/blog/2026-03-20-cve-2026-27896-go-json-mcp/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-20-cve-2026-27896-go-json-mcp/</guid><description>CVE-2026-27896 exploits Go&apos;s case-insensitive JSON parsing to bypass MCP security controls. Here is how the attack works, whether MCPProxy is affected, and what every Go-based MCP tool needs to fix.</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Pure BM25 Hits 14% Accuracy at Scale: What MCPProxy Needs Next</title><link>https://mcpproxy.app/blog/2026-03-19-bm25-accuracy-hybrid-search/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-19-bm25-accuracy-hybrid-search/</guid><description>BM25 achieves 14% Top-1 accuracy across 916 tools. Hybrid semantic+BM25 reaches 94%. Here is MCPProxy&apos;s roadmap from pure BM25 to hybrid search.</description><pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>BM25 vs Embeddings vs Lua: Comparing Approaches to the MCP Too Many Tools Problem</title><link>https://mcpproxy.app/blog/2026-03-19-bm25-vs-embeddings-vs-lua/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-19-bm25-vs-embeddings-vs-lua/</guid><description>MCP tool definitions consume 55K+ tokens. Four approaches compete to solve this: BM25, embeddings, Lua scripting, and built-in tool search. Here is how they compare.</description><pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>ContextCrush, DockerDash, and the Death of Trusted MCP Servers</title><link>https://mcpproxy.app/blog/2026-03-18-contextcrush-dockerdash-trusted-servers/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-18-contextcrush-dockerdash-trusted-servers/</guid><description>Two real-world MCP supply chain attacks prove the trusted server assumption is broken. ContextCrush weaponized a 50K-star server; DockerDash turned image metadata into RCE. Here is what gateway-level security looks like.</description><pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Why Docker Isolation for MCP Servers Isn&apos;t Optional — Lessons from 66 Zombie Containers</title><link>https://mcpproxy.app/blog/2026-03-18-docker-isolation-zombie-containers/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-18-docker-isolation-zombie-containers/</guid><description>Claude Code&apos;s MCP config silently orphans Docker containers. The community response is to abandon Docker — but that trades isolation for convenience. Here is why Docker done right beats no Docker at all.</description><pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Defense in Depth for MCP: Why Your Gateway Needs a Cryptographic Identity Layer</title><link>https://mcpproxy.app/blog/2026-03-18-defense-in-depth-mcp-identity/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-18-defense-in-depth-mcp-identity/</guid><description>The MCP security market has fragmented into distinct layers. MCPS adds cryptographic identity, MCPProxy provides gateway-level quarantine and isolation, and G0 handles static analysis. Here is why you need all three.</description><pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Perplexity&apos;s CTO Says MCP Eats Your Context Window — Here&apos;s How BM25 Discovery Fixes That</title><link>https://mcpproxy.app/blog/2026-03-18-perplexity-cto-bm25-context-window/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-18-perplexity-cto-bm25-context-window/</guid><description>Perplexity CTO Denis Yarats publicly moved away from MCP citing context window bloat. MCPProxy&apos;s BM25 tool discovery was built to solve exactly this problem — reducing 54K tokens to under 1K.</description><pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>We Analyzed the MCP Security Landscape in 2026 — Here&apos;s What Every Gateway Needs</title><link>https://mcpproxy.app/blog/2026-03-18-mcp-security-landscape-gateway-needs/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-18-mcp-security-landscape-gateway-needs/</guid><description>100% of MCP servers lack permission declarations, the average security score is 34/100, and the emerging security tooling stack is fragmenting fast. Here is what every MCP gateway needs to address.</description><pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>The MCP Gateway Landscape in 2026: Where MCPProxy Fits</title><link>https://mcpproxy.app/blog/2026-03-15-mcp-gateway-landscape/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-15-mcp-gateway-landscape/</guid><description>The MCP gateway market has exploded in 2026 with Microsoft, IBM, and Docker all shipping solutions. Here is how the landscape looks and where MCPProxy&apos;s BM25 discovery and quarantine set it apart.</description><pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Beyond BM25: The Future of MCP Tool Discovery</title><link>https://mcpproxy.app/blog/2026-03-15-beyond-bm25-tool-discovery/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-15-beyond-bm25-tool-discovery/</guid><description>New benchmarks show BM25 alone hits 14% top-1 accuracy for large tool sets. Here is what we have learned, why hybrid search is the future, and how MCPProxy is evolving.</description><pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>How MCPProxy Could Monitor MCP Server File Access Without Docker</title><link>https://mcpproxy.app/blog/2026-03-13-mcpproxy-filesystem-monitoring/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-13-mcpproxy-filesystem-monitoring/</guid><description>MCPProxy already provides Docker isolation, quarantine, and sensitive data detection. The next frontier: monitoring what files stdio MCP servers touch using OS-level sandboxing.</description><pubDate>Fri, 13 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Deep Dive: How MCPProxy Uses MCP Tool Annotations for Smarter Routing</title><link>https://mcpproxy.app/blog/2026-03-13-mcpproxy-tool-annotations-routing/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2026-03-13-mcpproxy-tool-annotations-routing/</guid><description>MCPProxy&apos;s DeriveCallWith system maps MCP tool annotations to read/write/destructive tool variants, enabling annotation-based access control and intent validation.</description><pubDate>Fri, 13 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Why BM25 Outperforms Vector Search for MCP Tool Discovery</title><link>https://mcpproxy.app/blog/why-bm25-outperforms-vector-search-for-mcp-tool-discovery/</link><guid isPermaLink="true">https://mcpproxy.app/blog/why-bm25-outperforms-vector-search-for-mcp-tool-discovery/</guid><description>When your AI agent connects to 20+ MCP servers with hundreds of tools, how do you find the right one? We chose BM25 over vector search — here&apos;s why.</description><pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Automated Testing for AI Agents: How to Build Regression Tests for MCP Tools</title><link>https://mcpproxy.app/blog/2025-08-27-mcp-evaluation/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2025-08-27-mcp-evaluation/</guid><description>Automated testing for AI agents is fundamentally different from traditional software testing due to non-deterministic behavior. This post surveys current approaches for evaluating Model Context Protocol (MCP) tool quality, and demonstrates how these methods are implemented in our open-source mcp-eval utility. We cover trajectory-based evaluation, similarity scoring, and practical Docker-based testing architectures that handle the inherent variability of LLM systems while maintaining testing reliability.</description><pubDate>Wed, 27 Aug 2025 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item><item><title>Productivity Tools for AI Agents</title><link>https://mcpproxy.app/blog/2025-08-10-productivity-tools-for-ai-agents/</link><guid isPermaLink="true">https://mcpproxy.app/blog/2025-08-10-productivity-tools-for-ai-agents/</guid><description>The Model Context Protocol (MCP), challenges of direct tool integration, and how MCPProxy solves tool overload with retrieval and security.</description><pubDate>Sun, 10 Aug 2025 00:00:00 GMT</pubDate><author>Algis Dumbris</author></item></channel></rss>