

D2DO276: MCP: Capable, Insecure, and On Your Network Today
Jun 25, 2025
Dan Barr, a Senior Technical Marketing Engineer at StackLock, dives deep into the Model Context Protocol (MCP), an open-source tool that connects AI agents to various data sources and applications. He shares insights on the strengths and vulnerabilities of MCP, especially around secure credential management and OAuth challenges. The podcast also introduces ToolHive, a solution for enhancing MCP security and managing microservices communication. Listeners will gain a better understanding of the complexities involved in leveraging AI in today's infrastructure.
AI Snips
Chapters
Transcript
Episode notes
Dan's Storage System Anecdote
- Dan Barr shared an anecdote about his first shared storage system being for a VMware cluster using HPE's own storage solution before acquisitions.
- He found old customers still relying on this outdated system and urged them to upgrade.
MCP Empowers AI Agents
- MCP is an open standard for connecting AI systems to external tools, likened to USB-C for AI.
- It gives AI agents hands, enabling them to operate on real-world tasks beyond their static training data.
Authorize Tool Use Carefully
- Always authorize tool use by AI agents to avoid unintended actions.
- Avoid auto-authorizing tools unless you want fully automated workflows, as manual prompts provide safety.