MCP servers, resources, and trust boundaries
By the end of today you have built a working MCP server, and you can name every trust boundary it introduces and who is responsible for each one.
YesterdayOn Day 84 you learned what the protocol standardises. Today you write one and find out what it leaves to you.
TomorrowTomorrow the phase turns to evaluation: knowing whether any of this actually works.
Why this matters
An MCP server is code that a model can invoke, often on behalf of users you did not anticipate, in applications you do not control. The boundaries multiply, and nothing in the protocol guards them for you.
- Building an MCP server
- MCP trust boundaries
- Acting as the user
- Scoping capabilities
Learn it
75 minCopy this into Claude or ChatGPT. It quizzes you before it explains anything, which is deliberate. The resources under it are how you check what it told you.
Today's Master Prompt
Free · sign inA prompt written for this day alone: your level, the exact scope, what to leave out, and an instruction to quiz you before it explains anything. Paste it into Claude or ChatGPT and it teaches you today's material.
Check it against something that is not a model
An assistant can be fluent and wrong, and on a topic you met today you will not catch it. These cover the same ground and were made by people who do this for a living, so they are what you hold the explanation up against. They are other people's work and we only link to them, so judge them for yourself.
3 hand-picked resources
Free · sign inVideos, official docs and articles covering the same ground, each opened and annotated by hand. They are what you check the assistant against on a day you cannot yet catch it being wrong.
Build it
55 minBuild an MCP server with two tools and one resource over a real system you control. Make every tool act as a specific user and enforce permissions inside the tool. Return a deliberately large result and observe what it does to the client's context. Then write down every trust boundary in your server and who is responsible for each.
Recall it
20 minAnswer out loud, reveal, then mark honestly whether you had it. That score is the only thing on this page you do not get to choose.
5 recall questions
Free · sign inQuestions you answer from memory, then grade yourself against the real answer. The score is carried into the mastery rating below it, so an honest miss cannot quietly become a tick.
Rate it
Completion and mastery are tracked separately. Be honest, because an inflated rating only means the concept resurfaces sooner.
Mastery tracking
Free · sign inRate yourself against five named criteria per concept. Completion and mastery are tracked separately, and anything you rate shakily comes back automatically on a spaced schedule.
Recap
- 01Everything a tool returns enters the model's context and can act as instruction
- 02The server must act with the user's permissions, never its own
- 03Narrow tools limit blast radius and are easier to use correctly
- 04A third-party server is a dependency with production access
Your progress
Free · sign inMark days complete, pick up where you left off across devices, and watch completion and mastery diverge. Free, and the account exists only so ninety days of work cannot vanish with a cleared browser.