Topic 12: Module 8 milestone and interview questions
Project Milestone
After this module, the running project has grown its security posture, not just its features. The canonical project now contains:
notes_assistant/pinning.py:fingerprint,pin_tools,save_pins,diff_pins,check_pins, andPinChange. Tool definitions can be pinned and diffed.notes_assistant/host.py: upgraded from the Module 6 version with apin_dirconfig field, aself.blockedmap, pin checking inload_tools, and a runtime refusal for blocked tools in_run_tool. Whenpin_dirisNonethe host behaves exactly as before, so the change is opt-in.- The approval gate (
needs_approval,deny_all,console_approve) from Module 6 now understood as the primary control for writes and outbound actions, not just a nicety. - A worked, measured understanding of the six MCP attack classes and the layered defence against them, ready to fold into the Module 11 capstone, which requires pinning tool definitions and warning on change, and a test that an injected note cannot trigger
create_notewithout approval.
The companion repository for this module adds, under examples/: m08_scripted_model.py, m08_poisoned_server.py, m08_rugpull_server.py, m08_shadow_server.py, m08_exfil_server.py, m08_gateway.py, the demos m08_demo_poisoning.py, m08_demo_pinning.py, m08_demo_rugpull.py, m08_demo_shadow.py, m08_demo_injection.py, m08_demo_exfil.py, m08_demo_gateway.py, plus m08_output_filter.py, m08_sandbox_stdio.py, m08_matrix.py, and m08_lab.py, and the mnotes/ folder holding a copy of the sample notes with one poisoned note added.