I built an MCP security gateway. Then I found the attack every layer allowed.

The architecture worked as designed. That was the problem: an untrusted tool result influenced a second, clean request that passed every control. The implementation evidence, the blind spot, and how it changed the design.

2026-07-19 · 39 min · Alexander Romanov

AI agents are talking to everything. Nobody agreed on who can ask.

MCP fragmentation isn’t a developer-experience problem — it’s a security surface. Part 1: why there’s no single place to ask whether an AI-agent tool call should happen.

2026-06-28 · 11 min · Alexander Romanov

Mediate, don't classify: the design of a runtime MCP security gateway

The architecture that gives AI-agent tool calls a single place to be decided: one gateway, one port, six checks, per-identity profiles, and brokered credentials. No code — just the design and the trust boundaries.

2026-06-28 · 9 min · Alexander Romanov