✕ Clear all filters
29 articles

📰 Dev.to · Rhumb

29 articles · Updated every 3 hours · View all reads

All Articles 72,036Blog Posts 101,122Tech Tutorials 17,502Research Papers 15,348News 12,911 ⚡ AI Lessons
MCP Fetch SSRF Protection Checklist
Dev.to · Rhumb 2w ago
MCP Fetch SSRF Protection Checklist
Prevent SSRF in MCP fetch and URL tools with URL parsing, DNS/IP classification, redirect containment, credential-lane isolation, typed denials, and audit recei
The First Paid Agent Call Should Be Boring
Dev.to · Rhumb 2w ago
The First Paid Agent Call Should Be Boring
Before an AI agent repeats a paid API call, make one route, one budget owner, one credential rail, one denied neighbor, and one receipt boring enough to audit.
MCP Threat Model Template for Agent Tools
Dev.to · Rhumb 2w ago
MCP Threat Model Template for Agent Tools
A copy-paste MCP threat model for production agent tools: route, caller, authority surface, credential lane, budget owner, denied neighbor, receipts, and recove
Resolve a web-search capability in three calls
Dev.to · Rhumb 1mo ago
Resolve a web-search capability in three calls
Most agent demos skip the governed preflight: supported path, concrete rail, cost, and credential boundary before spend.
Signed MCP Receipts Create Evidence After the Call. They Do Not Make the Call Safe
Dev.to · Rhumb 1mo ago
Signed MCP Receipts Create Evidence After the Call. They Do Not Make the Call Safe
Signed MCP Receipts Create Evidence After the Call. They Do Not Make the Call Safe A...
Persistent Agent Memory Works When Priors Are Bound, Not Merely Recalled
Dev.to · Rhumb 1mo ago
Persistent Agent Memory Works When Priors Are Bound, Not Merely Recalled
Persistent Agent Memory Works When Priors Are Bound, Not Merely Recalled A useful critique...
Static MCP Scores Are a Baseline. Runtime Trust Is the Missing Overlay
Dev.to · Rhumb 1mo ago
Static MCP Scores Are a Baseline. Runtime Trust Is the Missing Overlay
Static MCP Scores Are a Baseline. Runtime Trust Is the Missing Overlay A fresh critique of...
Remote MCP Uptime Is Not Production Readiness
Dev.to · Rhumb 1mo ago
Remote MCP Uptime Is Not Production Readiness
Remote MCP Uptime Is Not Production Readiness A remote MCP server that responds is not...
Governed Capabilities Are Becoming the Real Control Plane for Agent Integrations
Dev.to · Rhumb 🤖 AI Agents & Automation ⚡ AI Lesson 1mo ago
Governed Capabilities Are Becoming the Real Control Plane for Agent Integrations
Governed Capabilities Are Becoming the Real Control Plane for Agent Integrations A lot of...
Persistent Coding Memory Is a Trust Boundary, Not Just Context Compression
Dev.to · Rhumb 1mo ago
Persistent Coding Memory Is a Trust Boundary, Not Just Context Compression
Persistent Coding Memory Is a Trust Boundary, Not Just Context Compression A lot of...
Read-Only MCP Removes a Failure Class, But Only if the Whole Tool Boundary Is Actually Read-Only
Dev.to · Rhumb 🏗️ Systems Design & Architecture ⚡ AI Lesson 1mo ago
Read-Only MCP Removes a Failure Class, But Only if the Whole Tool Boundary Is Actually Read-Only
Read-Only MCP Removes a Failure Class, But Only if the Whole Tool Boundary Is Actually...
Flat \"Best MCP Server\" Lists Hide the Decision That Actually Matters: Workflow Fit vs Trust Class
Dev.to · Rhumb 1mo ago
Flat \"Best MCP Server\" Lists Hide the Decision That Actually Matters: Workflow Fit vs Trust Class
Flat "Best MCP Server" Lists Hide the Decision That Actually Matters: Workflow Fit vs Trust...
One Key, Many Superpowers: Why Agent Onboarding Should Be Capability-First
Dev.to · Rhumb 1mo ago
One Key, Many Superpowers: Why Agent Onboarding Should Be Capability-First
One Key, Many Superpowers: Why Agent Onboarding Should Be Capability-First A lot of agent...
MCP Credential Lifecycle: What Happens When Your Tokens Expire in Production
Dev.to · Rhumb 2mo ago
MCP Credential Lifecycle: What Happens When Your Tokens Expire in Production
Most MCP server operators discover their token management strategy the hard way: at 2am, when an...
Agent State Management: How to Build Workflows That Recover Without You
Dev.to · Rhumb 2mo ago
Agent State Management: How to Build Workflows That Recover Without You
Agent State Management: How to Build Workflows That Recover Without You ...
A Production Readiness Checklist for Remote MCP Servers
Dev.to · Rhumb 2mo ago
A Production Readiness Checklist for Remote MCP Servers
Remote MCP is not a convenience problem. It's an auth and containment problem. 7 questions every operator should answer before trusting a remote MCP server in p
How APIs Fail When Agents Use Them: A Failure Engineering Guide
Dev.to · Rhumb 2mo ago
How APIs Fail When Agents Use Them: A Failure Engineering Guide
Failure mode data is more operationally valuable than aggregate scores. Maps the six API failure categories — auth, rate limits, state consistency, network ambi
Designing Agent Fleets That Survive Rate Limits: A Production Architecture Guide
Dev.to · Rhumb 2mo ago
Designing Agent Fleets That Survive Rate Limits: A Production Architecture Guide
Rate limits aren't just API gotchas — they're fleet architecture constraints. Here's how to design multi-agent systems that handle rate limits at 2am without hu
LLM APIs in Agent Loops: What Actually Breaks at Scale
Dev.to · Rhumb 2mo ago
LLM APIs in Agent Loops: What Actually Breaks at Scale
Beyond benchmarks: how Anthropic, OpenAI, and Google AI actually behave when your agent is running autonomously at 2am. Tool calling fidelity, rate limit compli
Shopify API Autopsy: The GraphQL Bet That Agents Must Navigate
Dev.to · Rhumb 2mo ago
Shopify API Autopsy: The GraphQL Bet That Agents Must Navigate
Shopify powers 4.6 million stores and processes $235B+ in annual GMV. Its bet on GraphQL makes it one...