Tag:software-security
All the articles with the tag "software-security".
Selecting Fewer MCP Tools Is Not the Same as Enforcing Least Privilege
Updated:CommentaryDiscusses: The GitHub MCP Server adds support for tool-specific configuration, and more + 1 more
GitHub MCP tool filtering reduces context and accidental capability exposure, but real least privilege also requires identity, authorization, and effect controls.
Agentic Resource Discovery Still Needs a Verification Boundary
Updated:CommentaryDiscusses: Announcing the Agentic Resource Discovery specification + 1 more
ARD can help agents find capabilities across organizations, but discovery metadata must remain outside the trusted execution boundary.