CourseModel Context Protocol · Module 8: Security · part 54 of 83
Part 54 · Module 8: Security

Topic 9: Defences that work, and one that does not

8 min read·22 Sept 2026

You have now seen each defence stop a specific attack: the approval gate on writes and outbound calls, pinning on rug pulls, namespacing on shadowing, sandboxing on secret leakage. This part adds the one central control we have not built yet, a policy gateway, and then shows one popular idea that is not a defence, so you do not lean on it.

Least privilege, restated as a checklist

Least privilege means each tool, and each session, gets the smallest capability that does the job. Applied to the notes assistant:

  • The model gets search_notes (read-only) freely and create_note (write) only behind approval. That is needs_approval plus deny_all from Module 6.
  • A session that only needs to answer questions should not load a write tool or an outbound tool at all. The best-controlled outbound call is the one that is not present.
  • Downstream credentials in a proxy are scoped as narrowly as the task, per Part 6.

Least privilege is the cheapest defence because it removes outcomes instead of detecting them. Everything else in this part is about the outcomes you cannot remove.

The rest of this course is yours to keep

This course is bought on its own, once, and stays readable afterwards, including the parts added to it later.