AI Foundationspredict · compress · act
act IX

The Agent Infrastructure

MCP is to agents what USB was to peripherals: a standard plug so any model can use any tool without custom glue.

36

A Port for Tools

before this →Memory Outside the Weights

Every tool used to need custom integration for every model. The Model Context Protocol (MCP) is an open standard that decouples them: tool builders expose an MCP server, model apps speak to it as an MCP client, and any combination works.

BEFORE — N × Mcustom glue everywhereAFTER — N + MMCPprotocolone port, any pair
before MCP: every tool × every app. after: one protocol, any pair.

What MCP standardises

MCP defines how an agent discovers tools, calls them, and receives structured results. It also covers resources (data the server exposes, like files or records) and prompts (reusable templates). Servers can run locally or remotely, and a single client can connect to many servers at once — so a coding agent can use a filesystem server, a database server, and a browser server without any bespoke code.

Why it matters

Standards are how ecosystems scale. Before USB, every device had its own port. MCP is that moment for agents: tool authors publish once, app authors integrate once, and the combinatorial explosion of glue code becomes linear.

The new attack surface

a standard port is also a standard target

An MCP server is executable code with access to data and tools — and it may be third-party. A malicious server can serve poisoned resources or hide instructions in tool output. The protocol standardises connection; it does not make the far end trustworthy.

the practicePin and review servers, scope their permissions, and treat anything they return as untrusted input — because prompt injection lives in exactly that gap.
SERVERa tool or data source, exposed once
PROTOCOLdiscover, call, receive — standardised
CLIENTany agent app can use it
introduces →Model Context ProtocolMCP serverMCP clientinteroperability
← previousMemory Outside the Weightsnext →Many Hands, One Job