LLM

LLM Structured Outputs and JSON Schema: Tool Calling That Never Drifts

Free-form tool arguments are where agent workflows break: the model invents fields, sends numbers as strings, and omits required values. Structured outputs backed by strict JSON Schema make tool calls deterministic, and most of that schema already exists in your OpenAPI components.

4 min read

MCP Security in Practice: Prompt Injection, Least Privilege, and Audit Logs

MCP turns external content into actions: a tool description or API response is text the model reads and trusts, which makes indirect prompt injection a real attack path. Here is a practical threat model and the controls that actually work, from scoped tokens to human-in-the-loop and audit logs.

4 min read

MCP Tools vs Resources vs Prompts: What to Expose to an AI Agent

Most teams expose everything as MCP tools and end up with a catalog the model cannot navigate. The protocol defines three primitives for a reason: tools act, resources are readable context, and prompts package reusable workflows. Here is how to decide, with examples from an API platform.

3 min read