#mcp-server
A first customer is where a clean demo meets the messy input production refuses to simplify. ParseRail MCP Server is an MCP server for Claude, Cursor, any MCP client, with AI endpoints behind one API key and one pay-per-call credit wallet.

https://parserail.thecompound.tech/kb/5g2kkk
September 29, 2026 at 3:12 PM
Signs that an MCP Server is well built:

1) It thoughtfully limits the number of tools it exposes to the agent (to improve instruction following and reduce context bloat), and instead designs them as parameters to tool calls.
September 29, 2026 at 2:30 PM
how to create a MCP server for GSC in Claude?

1. Install uvx
2. create a service account in google cloud
3. use this

it uses aminfseo (on X) mcp-gsc package.
#buildinpublic
September 29, 2026 at 2:20 PM
how to create a MCP server for GSC in Claude?

1. Install uvx
2. create a service account in google cloud
3. use this
#buildinpublic
September 29, 2026 at 2:00 PM
Plus new Raku localisations (now including Bulgarian), a new website (Raku Koans), a new LLM Raku knowledge base interface (with MCP-server), and Raku++ by Andrew Shitov is now covering 100% of roast (and with that it is a new implementation of Raku). Each of these are exciting by themselves.
September 29, 2026 at 1:44 PM
kagent SandboxAgent has a native domain allowlist as well as role and tool bindings. MCP server credentials and resource-level rules still need their own native policies. Keep each permission in the existing format that actually enforces it.
Read more
The current kagent SandboxAgent API offers spec.sandbox.network.allowedDomains with default-deny outbound access for sandboxed execution, in addition to the declarative role, model and MCP tool bindings. This is a concrete existing format that gets closer to one file per agent. It does not turn a l…
cards.smith.wiki
September 29, 2026 at 12:44 PM
📌 CVE-2026-77271 - MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_safe_path defaults its ... https://www.cyberhub.blog/cves/CVE-2026-77271
CVE-2026-77271
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_safe_path defaults its base directory to os.getcwd(), and affected Confluence attachment call sites omit base_dir, allowing attacker-selected writes within the working direc
www.cyberhub.blog
September 29, 2026 at 12:37 PM
📝 Summary:

DBX is a compact (~25 MB) open-source database manager that unifies 100+ databases with a desktop app, Docker, CLI, and an AI-enabled editor, plus an MCP server for AI agents to safely query connected databases. It emphasizes a small footprint, offline-friendly binaries, plugin (1/2)
September 29, 2026 at 12:17 PM
🚀 Skyrocketing! 🚀 (200+ new stars)

📦 t8y2 / dbx
⭐ 21,647 (+460)
🗒 Rust

25 MB lightweight cross-platform database client for 100+ databases, including MySQL, PostgreSQL, SQLite, Redis, MongoDB, DuckDB, SQL Server, and Dameng. Built-in AI, MCP Server, CLI, desktop and Docker. | 轻量级跨平台数...
GitHub - t8y2/dbx: 25 MB lightweight cross-platform database client for 100+ databases, including MySQL, PostgreSQL, SQLite, Redis, MongoDB, DuckDB, SQL Server, and Dameng. Built-in AI, MCP Server, CLI, desktop and Docker. | 轻量级跨平台数据库管理工具,支持 MySQL、PostgreSQL、SQLite、Redis、MongoDB、达梦等 100+ 数据库,提供桌面端、Docker、CLI、内置 AI 助手和 MCP。
25 MB lightweight cross-platform database client for 100+ databases, including MySQL, PostgreSQL, SQLite, Redis, MongoDB, DuckDB, SQL Server, and Dameng. Built-in AI, MCP Server, CLI, desktop and D...
github.com
September 29, 2026 at 12:17 PM
📌 CVE-2026-77247 - MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence upload tools... https://www.cyberhub.blog/cves/CVE-2026-77247
CVE-2026-77247
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence upload tools interpret caller-controlled path arguments on the MCP server and open those files before sending them as attachments. In remote or multi-user deploym
www.cyberhub.blog
September 29, 2026 at 12:07 PM
MCP error messages tell the caller to run a terminal command or edit a config. Agents that can only call tools obey anyway: on expired credentials the loss grew from 18 points for GPT-5.5 to 69 for GPT-6 Astra. https://arxiv.org/abs/2609.35381
MCP Error Messages Written for Developers Hurt the Most Capable Agents Most
Many Model Context Protocol (MCP) servers wrap web APIs built for human developers, and their error messages tell the reader to run a command, edit a configuration, open a web page or wait. Many agents that read them can only call the server's tools. In 150 widely used MCP servers, 949 of 3,001 error messages tell the caller what to do next, and half of these steps depend on something the server cannot see about the caller. On credential errors, 62 of 67 steps ask for a terminal command, a configuration change or a web page; on rate limits, 20 of 30 say to wait and retry without naming the call to repeat. We tested five OpenAI models that act only through the tools of Berkeley Function Calling Leaderboard tasks, and the agents did what the step said. On expired credentials, a terminal command in the step left 45% of tasks recovered, and the loss it caused grew from 18 points for GPT-5.5 to 69 for GPT-6 Astra. On a rate limit, GitHub's "Wait before retrying." left 6%. We tested two remedies. For MCP developers, naming a server tool in the step raised recovery on expired credentials to 84%, with the login tool in place of the command, and on a rate limit to 88%, with the call to repeat in place of the bare wait. For agent developers, deleting the step with a one-sentence prompt before the model reads it raised recovery on expired credentials to 82%.
arxiv.org
September 29, 2026 at 12:06 PM
We gave Claude Code the LocalStack MCP server & a CSV export of SaaS billing data, then asked it to build a quarterly Revenue-by-Plan report. It loaded the data, found & fixed 2 bugs & proved the result, without ever touching the real Snowflake cloud! Read more: blog.localstack.cloud/test-snowfla...
Test Snowflake SQL Locally with Your AI Agent
We gave Claude Code the LocalStack MCP server and a CSV export of SaaS billing data, then asked it to build a quarterly Revenue-by-Plan report on our Snowflake emulator. It loaded the data, found &…
blog.localstack.cloud
September 29, 2026 at 11:46 AM
How can an AI agent read an email verification code without writing a regex?
_Sign-up forms stop agents with “we sent you a code”. The obvious fix, a six-digit regex over the inbox, works in a demo and breaks on real mail. Here is why, and the one call that replaces it._ > **TL;DR** Give the agent its own inbox, note the time, trigger the email, then call `GET /v1/inboxes/:id/verification` (SDK `waitForVerification`, MCP `get_verification_code`). It waits up to 60 seconds and returns the code or link with a confidence score. The extraction runs on our server the moment the email arrives, and an AI check confirms it is really a verification email. ## Why does a regex break on real sign-up emails? Because verification emails are full of other numbers. Order numbers, dates, prices, phone numbers, copyright years and ticket IDs all look like codes to `\d{6}`. And many codes don’t look like six digits at all: some are four or eight digits, some are letters and digits, some are split by a space or a hyphen. // The usual first attempt const code = message.text.match(/\b\d{6}\b/)?.[0]; // What it finds in real sign-up emails: // "Order 482913 confirmed" → 482913 (an order number) // "© 2026 Example Inc." → no match, but "2026" at 4 digits would be // "Call +1 415 555 0199" → no match, or part of a phone number // "Your code: KQ7-M2X" → no match (letters and a hyphen) // "G-583920 is your Google code" → 583920, luckily Links are worse. A sign-up email has a confirm button, but also “log in”, “manage preferences”, “unsubscribe”, tracking pixels and a privacy policy. Taking the first link can unsubscribe the agent instead of confirming it. And an agent that polls the inbox in a loop either waits too long or reads the previous code. ## What does Agentboxd do instead? Every inbound email is checked for a code or link the moment it is stored, before your agent asks. The rules favour precision, because a wrong code is worse than none: the agent can always read the message itself. * **Codes near the right words.** A candidate only counts close to a strong keyword (code, verification, OTP, passcode, 2FA, security code, PIN, and their equivalents in other languages) or, further in, a weaker one such as “sign in” or “confirm”. * **The usual impostors are rejected:** numbers glued to other numbers (phones, dates, card numbers), prices, labelled IDs (order, invoice, account, tracking), “error code”, “zip code”, promo codes, and years unless a strong keyword is right next to them. * **All the shapes codes come in:** 4 to 8 digits, or 6 to 10 letters and digits, with separators removed so you always get one canonical value (`482 913` → `482913`, `KQ7-M2X` → `KQ7M2X`, `G-583920` → `583920`). * **A code in the subject wins.** Otherwise the one closest to a keyword. * **Links by what they say.** The button text (verify, confirm, activate, magic link, reset) outranks the URL, so tracking-wrapped buttons still work. Unsubscribe, preferences, tracking and privacy links are never returned. On top of the pattern match, an AI classifier reads the email and answers one question: is this a login, one-time-code or confirm-your-email message? Pattern matching alone is capped at a confidence of 0.7. A clear yes from the classifier raises it to 0.95; a clear no drops it to 0.2. The classifier’s own answer is returned too, as `jev_probability`. How the classifier works is in How we classify every email an AI agent receives. ## How do you wait for the code? Three steps: note the time, trigger the email, wait. The wait endpoint holds the request open until a verification email newer than `since` arrives, up to 60 seconds, and returns the newest one, since the latest code is the valid one. No polling loop, no sleep. import { Agentboxd } from 'agentboxd'; const mr = new Agentboxd({ apiKey: process.env.AGENTBOXD_API_KEY! }); // 1. Note the time BEFORE triggering the email, so an older code can't be picked up. const since = new Date().toISOString(); // 2. Trigger the sign-up (browser automation, an API call, whatever your agent does). await signUpOnTheSite({ email: inbox.address }); // 3. Wait up to 60 seconds for the code or link to arrive. const v = await mr.messages.waitForVerification(inbox.id, { since, timeout: 60, from: 'example.com' }); if (!v) throw new Error('no verification email within 60 s'); if (v.confidence < 0.9) console.warn('low confidence: read the message', v.message_id); await enterCode(v.code ?? undefined); // or open v.link from datetime import datetime, timezone from agentboxd import Agentboxd mr = Agentboxd() # reads AGENTBOXD_API_KEY since = datetime.now(timezone.utc).isoformat() sign_up_on_the_site(email=inbox["address"]) v = mr.messages.wait_for_verification(inbox["id"], timeout=60, since=since, from_="example.com") if v is None: raise TimeoutError("no verification email within 60 s") print(v["code"] or v["link"], v["confidence"]) curl -s "https://api.agentboxd.com/v1/inboxes/$INBOX_ID/verification?timeout=60&since=2026-09-29T10:00:00Z&from=example.com" \ -H "Authorization: Bearer $AGENTBOXD_API_KEY" { "data": { "code": "583920", "link": null, "confidence": 0.95, "jev_probability": 0.97, "message_id": "0b3e8f4c-…", "from": "Example <no-reply@example.com>", "subject": "Your Example verification code", "received_at": "2026-09-29T10:00:07.412Z" } } Two details matter. Pass `since` from before you triggered the email: the default is the moment your request arrives, so a code that landed a second earlier would be missed. And pass `from` (a case-insensitive part of the sender) when the inbox is shared, so a code from another site can’t be picked up. On timeout you get `data: null`, not an error. ## What should the agent do with the confidence score? Confidence | What it means | Suggested action ---|---|--- 0.95 | Pattern found and the classifier confirmed a verification email | Use the code or link 0.5 – 0.7 | Pattern found, not confirmed yet (or AI processing is off for the workspace) | Use it for a sign-up you just started; otherwise read the message 0.2 | The classifier says this is not a verification email | Don’t use it; read the message ## Can the agent use a throwaway address for one sign-up? Yes. A temporary inbox is receive-only, lives on its own domain, and deletes itself and its mail when its time is up (1 minute to 24 hours, 15 minutes by default). Use it for trials and one-off sign-ups; keep a permanent inbox for accounts the agent will log back into. // A receive-only inbox that deletes itself (and its mail) after 15 minutes. const inbox = await mr.inboxes.createTemporary({ ttlSeconds: 900 }); const since = new Date().toISOString(); await signUpOnTheSite({ email: inbox.address }); const v = await mr.messages.waitForVerification(inbox.id, { since, timeout: 60 }); Some sites refuse known disposable domains. Temporary inboxes are on a separate domain for exactly that reason: if it gets listed, your permanent agent addresses are unaffected. If a site refuses it, use a permanent inbox. ## What can’t it do? * **SMS codes.** This is email only. * **CAPTCHAs.** They exist to stop software; we don’t help agents get around them. * **Codes inside images.** Only text and links are read. * **Decide whether the code should be used.** An email can claim to be a login code for a sign-up the agent never started. Only use codes and links for sign-ups the agent itself just triggered; our MCP server tells the model the same. ## FAQ ### Does it work with magic links as well as codes? Yes. The answer has `code`, `link` or both; one of them is set whenever a verification email was found. ### What if two emails arrive? You get the newest verification email after `since`. Codes are usually replaced when a new one is sent, so the newest is the one that works. ### Can I use it from Claude, Cursor or another MCP client? Yes: the `get_verification_code` tool does the same wait, and `create_temporary_inbox` makes a throwaway address. See the MCP server docs. ### Is the email content sent to an AI model? Only if the workspace allows AI processing (the default, `categorize`), and then only to the classifier, for the confirmation step. With AI processing off, the pattern match still returns the code, without the confirmation. Details in AI processing and privacy. Start with the quickstart: an inbox is one API call, and the free plan is enough to try this today. _Originally published on the Agentboxd blog._
dev.to
September 29, 2026 at 11:49 AM
📌 CVE-2026-77256 - MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the plaintext OAuth fallback fil... https://www.cyberhub.blog/cves/CVE-2026-77256
CVE-2026-77256
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the plaintext OAuth fallback file containing refresh and access tokens is written with permissions inherited from the process umask. Under common or permissive configurations, other
www.cyberhub.blog
September 29, 2026 at 11:37 AM
📌 CVE-2026-77248 - MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the streamable HTTP transport ac... https://www.cyberhub.blog/cves/CVE-2026-77248
CVE-2026-77248
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the streamable HTTP transport accepts requests without a user identity and falls back to operator credentials, while upload_attachment accepts an unrestricted file_path. An unauthent
www.cyberhub.blog
September 29, 2026 at 11:07 AM
🐟 New in Batfish: Nokia SR OS MD-CLI and Broadcom FASTPATH support, experimental Azure modelling, arm64 Docker images and a beta MCP server in pybatfish with 36 tools for AI agents.
➜ github.com/batfish/batf...
#networkautomation
September 29, 2026 at 11:01 AM
Many agent integrations stop at the API call. LazyRelay's MCP server also returns whether a post is really live, so the agent can check its own work. lazyrelay.com/mcp #MCP #AIAgents
September 29, 2026 at 10:30 AM