MCP: trust, scope, and minimal permissions
Model Context Protocol (MCP) connects your IDE to tool servers that can read files, call HTTP APIs, or query databases. That power is convenient—and dangerous if a server is malicious, misconfigured, or over-scoped. Treat MCP like installing a new background service: verify source, pin versions, and deny by default.
Widget tour: pipeline traces a single tool call; the table compares trust dimensions; the graph maps capabilities around the hub; text-blocks capture policy bullets.
Path of one MCP tool invocation
What to evaluate before you enable a server
Capability map (conceptual)
Policy snippets you can adopt