Nik Kale

Guest Author

Nik Kale is a principal engineer specializing in enterprise AI platforms and security. He is a contributor to the Coalition for Secure AI (CoSAI) through OASIS and the IETF OAuth working group, and serves on the program committee for ACM CCS 2026 and IEEE S&P SAGAI.

Planted prompt

MCP's new spec turns a planted prompt into a stolen credential

The Model Context Protocol's (MCP)'s largest revision since its initial launch shipped on July 28. By the end of the first day, all four Tier 1 SDKs were already speaking the new version, and Cloudflare's Agents SDK had support in place from day zero, with customers such as Sentry and Linear picking it up right away, meaning the surface this article describes is already live in production. A new 12-month deprecation policy keeps the changes in place through at least mid-2027. Most of the coverage has focused on what improvements have been made: A stateless core that scales on ordinary HTTP, OAuth-native authorization, and server-rendered UIs via MCP Apps.