Part III · Agents
Chapter 12
Tools, MCP and the Permission Model
Capabilities the system does not own: tools written by other people, whose schemas can change without consent and whose output goes straight into the prompt.
Deliverable: A governed tool supply chain — MCP with per-node scoping, an idempotency ledger, and result handling that treats output as untrusted input.
What's inside
10 topics
- 12.1What MCP Actually Standardises
- 12.2Server Topology and Transport
- 12.3Third-Party Tools as Untrusted Code
- 12.4Per-Node and Per-Tenant Tool Scoping
- 12.5Idempotent Tool Execution
- 12.6The Confused Deputy Problem
- 12.7Tool Result Handling
- 12.8Exposing Your Own Retrieval as a Tool
- 12.9Versioning and Capability Drift
- 12.10Three Tool Architectures Compared
Preparing PDF viewer…
A note on this content
The book and its chapters are my personal learning notes — compiled from online research and hands-on practice, with most of the content AI-generated from that research and learning. It is not a peer-reviewed publication, and I make no claim that it is 100% error-free. If you spot a mistake, I'd genuinely appreciate hearing about it — contact me.