Selecting Fewer MCP Tools Is Not the Same as Enforcing Least Privilege
GitHub MCP tool filtering reduces context and accidental capability exposure, but real least privilege also requires identity, authorization, and effect controls.
Software, data, computing platforms, networks, and operational information systems.
15 published materials across notes, projects, and publications.
Work whose central question belongs to Computing & Information Technology.
GitHub MCP tool filtering reduces context and accidental capability exposure, but real least privilege also requires identity, authorization, and effect controls.
Indexing, search, and RAG over a personal vault. Pipe’s, FAISS, integrations.
Work centred elsewhere that materially uses or informs Computing & Information Technology.
ARD can help agents find capabilities across organizations, but discovery metadata must remain outside the trusted execution boundary.
Counting tokens repeats an old measurement mistake unless AI-assisted work is evaluated through delivery, quality, and user outcomes.
Dependency diagrams can make mathematical papers easier to navigate, provided their inferred structure is not mistaken for verified proof evidence.
Agent stacks should be selected layer by layer, with explicit contracts for state, tools, memory, evaluation, and recovery.
Chain-of-thought prompting can improve some multi-step answers, but a plausible rationale is not evidence that an answer is correct or faithful.
Terence Tao's restored mathematical applets show where coding agents have real leverage—tasks whose outputs remain cheap for an expert to verify.
Slack's agent-driven E2E experiments expose a useful new execution model, but adaptation must remain separate from the authority to declare success.
Playwright's mature tooling makes it a strong default for new browser automation, but migration should be decided through a representative experiment.
Property-based testing is more than randomized input generation; its value depends on the property, distribution, oracle, shrinking, and evidence.
MetronForge is an independent research notebook for engineering observations, computational experiments, projects, and formal publications.
Pyramids, trophies, and honeycombs summarize different testing economics; a defensible strategy begins with risks, evidence, and feedback constraints.
Version control and CI improve documentation workflow, but a successful build cannot establish that instructions remain true, complete, or usable.
Pierre Pureur and Kurt Bittner correctly place decisions at the centre of architecture; their importance follows from reversal cost and blast radius.