The Dark Side of MCP Servers

The Dark Side of MCP Servers

Author: Demetrios June 23, 2026 Duration: 1:09:59

Sam Partee (CTO & co-founder of Arcade.dev) and Nate Barbettini (Founding Engineer at Arcade.dev) sit down at the MCP Dev Summit to unpack what nobody wants to admit about the Model Context Protocol: the security model is still full of sharp edges. From tool poisoning and prompt injection to why OAuth got bolted onto the spec, this is a builder 's-eye view of where MCP breaks — and how to ship agents safely anyway.

What we get into:🔓 OAuth on MCP — Why the spec adopted OAuth as its authorization standard, and the class of spoofing attacks it shuts down.☠️ Tool poisoning — How a malicious server hides instructions in tool descriptions, and why your agent trusts them by default.🧪 MCP Debugger & ToolBench — Shining a light on the rough edges by grading servers from S-tier to F-tier.🖥️ Sandboxing agents — Giving an agent a shell and a file system without handing over the keys to your machine.📜 Allow lists — Why MCP has client-level allow lists but skills mostly don't — and why that worries them.🔄 The auto-update problem — How skills and servers that silently update become a supply-chain risk ("rug pulls").✅ SOC 2, honestly — Why the controls are voluntary, misunderstood, and actually about best practices.🤖 AI-generated PRs — The new behaviors to watch for as agents start writing and merging code.

If you build agents, ship MCP servers, or are responsible for AI security at your company, this one's for you.

🔗 Links & ResourcesArcade.dev: https://www.arcade.devArcade MCP framework (GitHub): https://github.com/ArcadeAI/arcade-mcpSam Partee (GitHub): https://github.com/sparteeNate Barbettini (LinkedIn): https://www.linkedin.com/in/nbarbettiniMLOps.community: https://mlops.community

⏱️ Timestamps[00:00] Skills, agents, and local context

[08:36] MCP Debugger grades your server

[10:34] Why AI clients are still buggy

[20:54] Why agents shouldn’t always have shell access

[22:44] “I have a spicy take.”

[26:27] “Do not build your own auth.”

[31:14] The “checking someone else’s email” problem

[35:40] “OAuth is the best worst option.”

[43:50] The future of AI entertainment

[46:19] Tool poisoning explained

[50:49] “Trust me, bro,” is not a security solution

[52:45] MCP registries as the App Store model

[1:00:28] AI-generated PRs and speed vs quality

[1:02:37] Why behavior-driven development is coming back

[1:08:11] Have we already reached AGI?


#MCP #AIAgentSecurity #ToolPoisoning


Hosted by Demetrios, MLOps.community is a space for honest, meandering talks about the real work of making artificial intelligence systems actually work. This isn't about hype or theoretical papers; it's about the messy, practical, and often surprising journey of taking models from a notebook into a live environment. You'll hear from engineers and practitioners who are in the trenches, discussing the tools, the frustrations, and the occasional breakthroughs that define the day-to-day. The conversations are deliberately relaxed, covering everything from traditional machine learning pipelines to the new world of large language models and even the intangible "vibes" of team culture and process. Each episode peels back a layer on what "production" really means, whether that involves deploying a predictive service, managing an agentic system, or maintaining reliability as everything scales. Tuning into this podcast feels like grabbing a coffee with colleagues who aren't afraid to dig into the technical nitty-gritty while keeping the tone conversational and accessible. It's for anyone who builds, manages, or is just curious about the operational backbone that allows AI to deliver value, offering a grounded perspective often missing from the broader conversation.
Author: Language: en-us Episodes: 50

Agentic Conversations (formally mlops.community)
Podcast Episodes
Skills over MCP on the streets of Tokyo [not-audio_url] [/not-audio_url]

Duration: 32:30
Tool descriptions tell an agent what a tool does. They don't tell it how to use five tools together, in the right order, following your conventions. That gap is where this conversation lives.Filmed at AGNTCon + MCPCon in…
Walking Tokyo Talking Agent Protocols [not-audio_url] [/not-audio_url]

Duration: 28:49
Two people, a wrong turn into a back alley, a community garden, and about thirty minutes of arguing about protocols on the streets of Tokyo.The guest is Angie Jones, VP of Developer Experience at the Agentic AI Foundatio…
Why Cost Per Million Tokens Is A Useless KPI? [not-audio_url] [/not-audio_url]

Duration: 38:49
A year ago, Palo Alto Networks built dashboards to track AI spend. Today those dashboards are useless, and the team that built them thinks that's the whole story.Recorded at FinOps X in San Diego, this conversation bring…
The Five-Layer Cake Approach to Scaling AI Without Wasting Money [not-audio_url] [/not-audio_url]

Duration: 38:55
In this episode of Agentic Conversations, we sit down with Ambud Sharma, Principal Engineer at Pinterest, responsible for general technology efficiency, fresh off delivering a controversial keynote on AI infrastructure o…
The Winchester Mystery House Problem in AI Development [not-audio_url] [/not-audio_url]

Duration: 59:41
AI models are starting to act like appliances, locked into one narrow way of working, instead of the flexible infrastructure they used to be. Drew Breunig, an AI and data strategist working with the Overture Maps Foundat…
How Predictive Analytics Stops Budget Overruns Before They Happen? [not-audio_url] [/not-audio_url]

Duration: 29:23
Every engineer at Wayfair can now see, in real time, exactly what their code costs, and that's on purpose. Brent Eubanks, FinOps Architect at Wayfair, walks us through what happens when you stop treating AI spend as a fi…
How To Delegate To An Agent Like You Would An Employee? [not-audio_url] [/not-audio_url]

Duration: 55:15
OpenAI's Codex developer experience lead sits down with a former comedian turned ML engineering lead for a conversation about what happens when computer use agents stop being a novelty and start actually running your day…
Why Your AI Bill Will Double Before It Gets Better [not-audio_url] [/not-audio_url]

Duration: 32:24
In this episode, we're joined by Josh Collier, FinOps Lead at Superhuman (formerly Grammarly), to explore what it really costs to run AI at scale and why the rules of the game changed faster than anyone expected.We discu…
MCP Goes Stateless [not-audio_url] [/not-audio_url]

Duration: 52:27
David Soria Parra is an Engineering Lead at Anthropic and one of the core maintainers of the Model Context Protocol (MCP). We explore the biggest evolution of the protocol since its launch, and why MCP is becoming the fo…
AI Hype vs. Real Value [not-audio_url] [/not-audio_url]

Duration: 42:37
Manish Dasaur is a Managing Director at PwC with over 20 years in data and AI, having helped 100+ clients navigate AI disruption and extract real business value from data, AI, and agentic AI initiatives. In this episode,…