Facio Blog

Practical notes on human-reviewed AI agents.

Payload-powered product notes, security writing, HITL patterns, and operational guidance from the Facio runtime: long sessions, Placet approvals, audit trails, memory, providers, channels, tools, and Docker-first operations.

Clear

Showing 6-10 of 76 articles in Engineering.

Engineering

MCP Spotlight: Linear MCP Server — The Official Engineering-Execution Bridge With Read-by-Default Tools, Project Status Updates, and the Issue-Tracking Default for Agents

Jul 30, 2026Engineering

MCP Spotlight: Linear MCP Server — The Official Engineering-Execution Bridge With Read-by-Default Tools, Project Status Updates, and the Issue-Tracking Default for Agents

The official Linear MCP Server by Linear — ~25 focused tools covering issues, projects, cycles, initiatives, customers, with read-by-default semantics and structured filter syntax. OAuth 2.0 with principle-of-least-privilege scopes. Project update primitive for stakeholder communication. MIT-licensed.

Engineering

MCP Spotlight: Memory MCP Server — Anthropic's Reference Implementation for Persistent Knowledge Graphs, Entity-Relation Schema, and the Long-Term-Memory Default for Agents

Jul 29, 2026Engineering

MCP Spotlight: Memory MCP Server — Anthropic's Reference Implementation for Persistent Knowledge Graphs, Entity-Relation Schema, and the Long-Term-Memory Default for Agents

The official Memory MCP Server by Anthropic — 9 tools (create_entities, create_relations, add_observations, search_nodes, open_nodes, read_graph, delete_*) built around a knowledge graph primitive. Local JSON file persistence by default. Typed entities + typed relations + append-only observations. MIT-licensed.

Engineering

MCP Security Threat Model 2026: Prompt Injection, Agentjacking, Tool Squatting, and the Defense-in-Depth Every Production Deploy Needs

Jul 28, 2026Engineering

MCP Security Threat Model 2026: Prompt Injection, Agentjacking, Tool Squatting, and the Defense-in-Depth Every Production Deploy Needs

The MCP security threat model in 2026 — five recurring patterns (prompt injection via tool output, agentjacking via attacker events, tool squatting via name collisions, supply-chain via malicious servers, credential leakage via misconfigured transports). Defense-in-depth stack with output sanitization, signature verification, isolation, RBAC, HITL gating, audit trail.

Engineering

MCP Registry Landscape 2026: From `mcp://` URLs to Verified Catalogs, and Why Curated Distribution Beats npm-Universe Trust

Jul 27, 2026Engineering

MCP Registry Landscape 2026: From `mcp://` URLs to Verified Catalogs, and Why Curated Distribution Beats npm-Universe Trust

The MCP registry landscape in 2026 — Docker MCP Catalog (production default, signed + provenanced), Official MCP Servers (Anthropic-maintained references), Glama (discovery), Smithery (community + npm), mcp.so/AIPOLABS (curated lists). Defense-in-depth distribution with signature + provenance + isolation + RBAC + HITL.

Engineering

MCP Spotlight: Cloudflare MCP Server — The 2,500-Endpoint Edge Bridge With Code Mode, Two-Tool Minimalism, and the API-Default Reference for Agents

Jul 26, 2026Engineering

MCP Spotlight: Cloudflare MCP Server — The 2,500-Endpoint Edge Bridge With Code Mode, Two-Tool Minimalism, and the API-Default Reference for Agents

The official Cloudflare MCP Servers by Cloudflare — 2 tools in the Code Mode profile (mcp_search, mcp_execute) giving access to all 2,500+ Cloudflare API endpoints with bounded context. Plus 13+ specialized product servers. MIT-licensed. The edge-infrastructure default for AI agents in 2026.