DeepThinking AI

Tag

security

Covered in AI EngineeringAgents & Protocols, where the background and the sources for this subject live.

AI Engineering

Do robots.txt and llms.txt stop AI agents from writing?

robots.txt, llms.txt, Content-Signal and AIPREF all describe what an agent may fetch. The 2,000 packages uploaded to RubyGems in May went through a signup form and a publish endpoint, which none of those files govern. Read controls are advisory. Write paths need identity and rate limits.

3 min read

Agents & Protocols

Does MCP verify tool definitions the way it verifies skills?

SEP-2640 reached Final status and landed in the MCP docs on 13 September 2026. It requires hosts to verify every skill file against a SHA-256 digest and byte size, and binds approval to that manifest so one changed file revokes it. The tools primitive specifies none of this. MCP now has two content surfaces with opposite integrity models.

3 min read