Fetching from the wire…
Markets2026-09-04 · source-backed
The Tool Definition Quality Score scores MCP tool definitions on six weighted per-tool dimensions and four server-level ones. The live registry numbers are what's new: 228,369 tools scored, 97% with description defects, 73.5% still clearing the B-tier passing bar, well-described tools picked about 2.6x more often, and rewriting descriptions alone improving task success by about 6 percentage points. If MCP is a distribution channel, the tool description is the listing copy, and a 2.6x selection lift from prose changes is the cheapest optimization available to anyone shipping a server. TDQS
Each link below shares sources, entities, or timing with this story.
This one rearranged my week. An essay published August 4 walks through Databricks' independent benchmark of coding harnesses against its own multi-million-line codebase. Pi, a harness with four built-in tools and a system prompt under 1,000 tokens, paired with Opus 4.8 at xhig...
The Model Context Protocol has a security problem that's no longer theoretical — it's statistical. Between January and February 2026, researchers filed 30+ CVEs against MCP servers, clients, and infrastructure. One package with nearly 500,000 downloads carried a CVSS 9.6 RCE....
WebMCP in Chrome 146 Canary is flying under the radar but could be transformative. Two APIs: the Declarative API adds tool names/descriptions to existing HTML forms with minimal code changes. The Imperative API handles complex interactions via JavaScript tool schemas (similar...
Released September 2, this build fixes managed settings silently going unenforced when the managed-settings file, a drop-in, the MDM plist, or the HKLM value fails to parse. Claude Code now refuses to launch and names the source. It also fixes concurrent sessions silently reve...
TrustMeBro is a Go tool at 327 stars, created August 26, that intercepts commands invoked by Codex, Claude Code and pi through PATH shims alone. No plugin, no hook, no MCP. Rules decide whether to fabricate output, rewrite stdout while preserving stderr and exit status, block,...
The result-interception hook (#41202) is a place to redact secrets or strip injected instructions out of untrusted MCP output before it enters context, which is the missing seam in every MCP setup I've built. Also: a configurable grace period for discovering tools from optiona...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.