CourseModel Context Protocol · Module 8: Security · part 57 of 83
Part 57 · Module 8: Security

Topic 12: Module 8 milestone and interview questions

8 min read·22 Sept 2026

Project Milestone

After this module, the running project has grown its security posture, not just its features. The canonical project now contains:

  • notes_assistant/pinning.py: fingerprint, pin_tools, save_pins, diff_pins, check_pins, and PinChange. Tool definitions can be pinned and diffed.
  • notes_assistant/host.py: upgraded from the Module 6 version with a pin_dir config field, a self.blocked map, pin checking in load_tools, and a runtime refusal for blocked tools in _run_tool. When pin_dir is None the host behaves exactly as before, so the change is opt-in.
  • The approval gate (needs_approval, deny_all, console_approve) from Module 6 now understood as the primary control for writes and outbound actions, not just a nicety.
  • A worked, measured understanding of the six MCP attack classes and the layered defence against them, ready to fold into the Module 11 capstone, which requires pinning tool definitions and warning on change, and a test that an injected note cannot trigger create_note without approval.

The companion repository for this module adds, under examples/: m08_scripted_model.py, m08_poisoned_server.py, m08_rugpull_server.py, m08_shadow_server.py, m08_exfil_server.py, m08_gateway.py, the demos m08_demo_poisoning.py, m08_demo_pinning.py, m08_demo_rugpull.py, m08_demo_shadow.py, m08_demo_injection.py, m08_demo_exfil.py, m08_demo_gateway.py, plus m08_output_filter.py, m08_sandbox_stdio.py, m08_matrix.py, and m08_lab.py, and the mnotes/ folder holding a copy of the sample notes with one poisoned note added.

The rest of this course is yours to keep

This course is bought on its own, once, and stays readable afterwards, including the parts added to it later.