Deep-dive guides on AI agents, agent orchestration, MCP, and developer tooling.
7 posts found
Tools and resources get all the attention in MCP, but sampling is the primitive that inverts the relationship — letting a server without its own model borrow the client's LLM through a two-gate approval flow.
When an LLM agent calls the wrong tool or sends malformed arguments, the postmortem usually blames the model — but the actual defect is almost always in the JSON Schema the tool was registered with.
AI coding assistants aren't one architecture — they're three separable design decisions (how context gets assembled, how edits get applied, how execution gets contained) that every tool from Claude Code to Cursor answers differently.
In agent systems, instructions live across four surfaces — system prompt, tool schemas, tool results, and few-shot text — not one. Most prompt debugging still only looks at the first.
Most agent security advice targets prompt injection at the wrong layer. The real fix is architectural: separate untrusted tool output from privileged context, scope tool capabilities narrowly, and gate side-effecting actions behind confirmation.