MCP (Model Context Protocol)
MCP is an open standard, introduced by Anthropic, for how applications expose tools and data to LLMs, so a tool built once can be reused across different LLM apps.
MCP (Model Context Protocol) is an open standard, introduced by Anthropic in late 2024, that standardizes how applications expose tools and data to LLMsLLM (Large Language Model)An LLM is a large transformer trained to predict the next token on massive text corpora, then fine-tuned to follow instructions — the architecture behind GPT, Claude, Gemini, and Llama.. Before MCP, every application wiring an LLM to its own tools needed a bespoke integration; MCP lets a tool built once be reused across different LLM-powered applications and agentsAgentAn agent puts an LLM in a loop with tool access, letting it decide autonomously which tools to call and in what order to accomplish a multi-step goal. — similar to how a USB standard means a peripheral doesn't need custom wiring for every computer.
How it works
MCP is a client–server protocol built on JSON-RPC 2.0. The host application (an editor, a chat client, an agent runtime) runs an MCP client for each server it connects to; servers run either as a local subprocess over stdio or as a remote HTTP endpoint.
On connection the two sides exchange capabilities, then the client calls
tools/list, resources/list, and prompts/list to discover what the
server offers. Tools are functions with JSON Schema inputs that the
model can invoke via tools/call; resources are
read-only context the host can attach; prompts are reusable templates a
user can select. The model itself never speaks MCP — the host
translates discovered tool schemas into whatever tool-calling format its
model API expects, and translates the model's chosen call back into an
MCP request.
When it breaks
- Tool descriptions are prompt surface. Every listed tool's name and description is injected into context, so a server exposing dozens of tools burns tokens and degrades selection accuracy. Curation beats coverage.
- A server is code you are trusting. It runs with the host's privileges and its descriptions reach the model directly, which makes a malicious or compromised server a prompt injectionPrompt InjectionPrompt injection is an attack where text an LLM processes — user input, a retrieved document, or a tool's output — contains instructions that override the application's intended behavior. vector.
- Schemas do not guarantee behaviour. Models still emit arguments that validate but are semantically wrong — a plausible file path, an invented ID — so servers need their own validation.
- Protocol churn. The spec and transports have moved quickly; client and server versions drift and fail in confusing ways.
See also: AgentAgentAn agent puts an LLM in a loop with tool access, letting it decide autonomously which tools to call and in what order to accomplish a multi-step goal., LLMLLM (Large Language Model)An LLM is a large transformer trained to predict the next token on massive text corpora, then fine-tuned to follow instructions — the architecture behind GPT, Claude, Gemini, and Llama.
Learn more: Agents & Tool Use · MCP official site
Mentioned in
Lessons where this comes up in context.
- Agents & Tool UseGiving an LLM the ability to take actions and chain multiple steps together — tool use, MCP, and the agent loop
- AI SecurityAdversarial misuse of a deployed AI system — prompt injection, jailbreaks, data exfiltration via tool use, adversarial examples, and the red-teaming practice that hunts for all of them
Agent
An agent puts an LLM in a loop with tool access, letting it decide autonomously which tools to call and in what order to accomplish a multi-step goal.
Benchmark
A benchmark is a fixed, standardized set of test questions used to compare models on a specific capability — reproducible, but vulnerable to contamination and saturation.