Web2 stack: API → abuse → OAuth → fraud systems MCP stack (today): API → ??? We skipped the painful lessons. Agents won’t wait for us to catch up.
- 0 replies
- 0 recasts
- 0 reactions
First version of MCP infra: “verify the request” Next version: “verify the agent” Final version: “price the risk of the agent in real time” Anything before that is just soft security.
- 0 replies
- 0 recasts
- 0 reactions
MCP servers are about to learn the same lesson DeFi did: permissionless ≠ trustless If your agent can: - show up with a token - pass basic validation - and execute actions You didn’t build infra. You built an attack surface. Identity + reputation isn’t optional. It’s the base layer.
- 0 replies
- 0 recasts
- 0 reactions