The Dark Side of MCP Servers

The Dark Side of MCP Servers

Author: Demetrios June 23, 2026 Duration: 1:09:59

Sam Partee (CTO & co-founder of Arcade.dev) and Nate Barbettini (Founding Engineer at Arcade.dev) sit down at the MCP Dev Summit to unpack what nobody wants to admit about the Model Context Protocol: the security model is still full of sharp edges. From tool poisoning and prompt injection to why OAuth got bolted onto the spec, this is a builder 's-eye view of where MCP breaks — and how to ship agents safely anyway.

What we get into:🔓 OAuth on MCP — Why the spec adopted OAuth as its authorization standard, and the class of spoofing attacks it shuts down.☠️ Tool poisoning — How a malicious server hides instructions in tool descriptions, and why your agent trusts them by default.🧪 MCP Debugger & ToolBench — Shining a light on the rough edges by grading servers from S-tier to F-tier.🖥️ Sandboxing agents — Giving an agent a shell and a file system without handing over the keys to your machine.📜 Allow lists — Why MCP has client-level allow lists but skills mostly don't — and why that worries them.🔄 The auto-update problem — How skills and servers that silently update become a supply-chain risk ("rug pulls").✅ SOC 2, honestly — Why the controls are voluntary, misunderstood, and actually about best practices.🤖 AI-generated PRs — The new behaviors to watch for as agents start writing and merging code.

If you build agents, ship MCP servers, or are responsible for AI security at your company, this one's for you.

🔗 Links & ResourcesArcade.dev: https://www.arcade.devArcade MCP framework (GitHub): https://github.com/ArcadeAI/arcade-mcpSam Partee (GitHub): https://github.com/sparteeNate Barbettini (LinkedIn): https://www.linkedin.com/in/nbarbettiniMLOps.community: https://mlops.community

⏱️ Timestamps[00:00] Skills, agents, and local context

[08:36] MCP Debugger grades your server

[10:34] Why AI clients are still buggy

[20:54] Why agents shouldn’t always have shell access

[22:44] “I have a spicy take.”

[26:27] “Do not build your own auth.”

[31:14] The “checking someone else’s email” problem

[35:40] “OAuth is the best worst option.”

[43:50] The future of AI entertainment

[46:19] Tool poisoning explained

[50:49] “Trust me, bro,” is not a security solution

[52:45] MCP registries as the App Store model

[1:00:28] AI-generated PRs and speed vs quality

[1:02:37] Why behavior-driven development is coming back

[1:08:11] Have we already reached AGI?


#MCP #AIAgentSecurity #ToolPoisoning


Hosted by Demetrios, MLOps.community is a space for honest, meandering talks about the real work of making artificial intelligence systems actually work. This isn't about hype or theoretical papers; it's about the messy, practical, and often surprising journey of taking models from a notebook into a live environment. You'll hear from engineers and practitioners who are in the trenches, discussing the tools, the frustrations, and the occasional breakthroughs that define the day-to-day. The conversations are deliberately relaxed, covering everything from traditional machine learning pipelines to the new world of large language models and even the intangible "vibes" of team culture and process. Each episode peels back a layer on what "production" really means, whether that involves deploying a predictive service, managing an agentic system, or maintaining reliability as everything scales. Tuning into this podcast feels like grabbing a coffee with colleagues who aren't afraid to dig into the technical nitty-gritty while keeping the tone conversational and accessible. It's for anyone who builds, manages, or is just curious about the operational backbone that allows AI to deliver value, offering a grounded perspective often missing from the broader conversation.
Author: Language: en-us Episodes: 50

Agentic Conversations (formally mlops.community)
Podcast Episodes
Sandboxing, Agent Harnesses, and Agent Teamwork [not-audio_url] [/not-audio_url]

Duration: 1:19:53
Shahram Anver is the Co-Founder and CEO of Cleric, the autonomous AI SRE that investigates and root-causes production issues like an experienced teammate — often in under two minutes. Before Cleric, Shahram led MLOps, De…
MCP Servers Are Becoming the UI for AI Agents [not-audio_url] [/not-audio_url]

Duration: 47:21
Naseem Al-Naji is the co-founder of MCPcat.io and the creator of Opal — a builder with deep roots in privacy-first developer tooling. In this conversation, he breaks down why MCP servers have become a black box in produc…
Agents & the $40M Bet on Multiplayer AI [not-audio_url] [/not-audio_url]

Duration: 1:20:46
Stanislas Polu is Co-Founder & CTO of Dust — the enterprise AI agent platform used by 51,000 workers at 3,000+ companies. Before Dust, he spent three years on OpenAI's research team under Ilya Sutskever, working on mathe…
From Single-Player to Multi-Player: Operating AI Agents at Scale [not-audio_url] [/not-audio_url]

Duration: 55:54
James Everingham is the CEO and Co-founder of Guild.ai — the AI agent control plane for production teams. With roots at Netscape, Instagram (Head of Engineering), and Meta (Head of Dev Infra, leading a 1,000-person org),…
The Control-vs-Magic Spectrum Building Agents [not-audio_url] [/not-audio_url]

Duration: 43:18
Thiago Cardoso is the Director of Data & AI at iFood and the architect behind iFood Pago's AI agent platform. This fintech system serves millions of restaurants across Brazil through WhatsApp and the iFood app. In this e…
Logs Are All You Need: Rethinking Observability with AI Agents [not-audio_url] [/not-audio_url]

Duration: 46:39
Sherwood Callaway is the founder of Sazabi (YC P26), the AI-native observability platform built for engineering teams who ship fast. He previously founded and exited a YC company — now he's back, betting that logs are al…
AI Is Fast. AI Projects Are Slow. Let's Fix That. [not-audio_url] [/not-audio_url]

Duration: 56:47
Joe Maionchi (Co-founder & COO) and Rod Christensen (Co-founder & Chief Architect) of RocketRide join the MLOps Community to walk through AIDE — the AI Integrated Development Environment. RocketRide is an open-source AI…
Architecting Modern AI Systems: Platforms, Agents, and Integration [not-audio_url] [/not-audio_url]

Duration: 56:59
BuzzHPC Roundtable episode: Architecting Modern AI Systems: Platforms, Agents, and Integration Join the Community: https://go.mlops.community/YTJoinInGet the newsletter: https://go.mlops.community/YTNewsletterMLOps GPU G…
[Special Announcement] MLOps Community Linux Foundation [not-audio_url] [/not-audio_url]

Duration: 2:19
Big news: the MLOps Community is joining the Linux Foundation to become the official user community of the new Agentic AI Foundation (AAIF). The AAIF is the neutral home for open source projects like the Model Context Pr…