
MLOps.community · 2026-06-23 · 1h 10m
Sam Partee (CTO & co-founder of Arcade.dev) and Nate Barbettini (Founding Engineer at Arcade.dev) sit down at the MCP Dev Summit to unpack what nobody wants to admit about the Model Context Protocol: the security model is still full of sharp edges. From tool poisoning and prompt injection to why OAuth got bolted onto the spec, this is a builder 's-eye view of where MCP breaks - and how to ship agents safely anyway. What we get into: OAuth on MCP - Why the spec adopted OAuth as its authorization standard, and the class of spoofing attacks it shuts down.️ Tool poisoning - How a malicious server hides instructions in tool descriptions, and why your agent trusts them by default. MCP Debugger & ToolBench - Shining a light on the rough edges by grading servers from S-tier to F-tier.️ Sandboxing agents - Giving an agent a shell and a file system without handing over the keys to your machine. Allow lists - Why MCP has client-level allow lists but skills mostly don't - and why that worries them. The auto-update problem - How skills and servers that silently update become a supply-chain risk ("rug pulls").