<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Byron DG — The Upstream</title><link>https://byrondgdev.com/tags/security/</link><description>Recent content in Security on Byron DG — The Upstream</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 20 Jul 2026 15:55:47 -0400</lastBuildDate><atom:link href="https://byrondgdev.com/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>The Gateway That Forgot Who Was Calling</title><link>https://byrondgdev.com/posts/the-gateway-that-forgot-who-was-calling/</link><pubDate>Mon, 20 Jul 2026 09:00:00 +0000</pubDate><guid>https://byrondgdev.com/posts/the-gateway-that-forgot-who-was-calling/</guid><description>&lt;p&gt;My agents have a tool problem, and it is the good kind of problem, the kind you earn. Most new capabilities I add ship as &lt;a href="https://byrondgdev.com/recall/mcp/"&gt;MCP&lt;/a&gt; servers, and the more comfortable I get with the protocol, the more often I reach for it. MCP is the protocol that lets an AI agent call external tools: one server exposes search over my research library, another sends messages between agents, another fetches web pages, and so on. Each one is useful. But each one is also its own entrance: every server an agent connects to is a separate door with its own lock, or worse, no lock at all.&lt;/p&gt;</description></item></channel></rss>