
MCP's new spec turns a planted prompt into a stolen credential
The Model Context Protocol's (MCP)'s largest revision since its initial launch shipped on July 28. By the end of the first day, all four Tier 1 SDKs were already speaking the new version, and Cloudflare's Agents SDK had support in place from day zero, with customers such as Sentry and Linear picking it up right away, meaning the surface this article describes is already live in production. A new 12-month deprecation policy keeps the changes in place through at least mid-2027. Most of the coverage has focused on what improvements have been made: A stateless core that scales on ordinary HTTP, OAuth-native authorization, and server-rendered UIs via MCP Apps.
































