<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Storm</title>
    <description>The latest articles on DEV Community by Storm (@stormliveai).</description>
    <link>https://dev.to/stormliveai</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4123195%2F7d2d07d9-ab38-463e-aec2-9c47db9bbf17.png</url>
      <title>DEV Community: Storm</title>
      <link>https://dev.to/stormliveai</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/stormliveai"/>
    <language>en</language>
    <item>
      <title>Hardening Your MCP Architecture: Security Best Practices for Claude Desktop &amp; Cursor</title>
      <dc:creator>Storm</dc:creator>
      <pubDate>Mon, 14 Sep 2026 05:17:09 +0000</pubDate>
      <link>https://dev.to/stormliveai/hardening-your-mcp-architecture-security-best-practices-for-claude-desktop-cursor-3k</link>
      <guid>https://dev.to/stormliveai/hardening-your-mcp-architecture-security-best-practices-for-claude-desktop-cursor-3k</guid>
      <description>&lt;p&gt;Giving an AI assistant access to your local filesystem, databases, and Docker daemon via the Model Context Protocol (MCP) unlocks tremendous productivity. But running untrusted or misconfigured MCP servers introduces critical security risks.&lt;/p&gt;

&lt;p&gt;Here are the four essential security hardening patterns every engineering team should implement:&lt;/p&gt;

&lt;h3&gt;
  
  
  1. Defend Against Tool Description Poisoning
&lt;/h3&gt;

&lt;p&gt;When an MCP client queries &lt;code&gt;tools/list&lt;/code&gt;, it consumes natural language descriptions of every available tool. A compromised third-party package can inject prompt overrides directly into the tool description string (e.g. instructing the model to exfiltrate context or silently bypass confirmation dialogs).&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Rule:&lt;/em&gt; Only install verified servers from trusted registries like &lt;a href="https://mcpbridge.org/directory/?utm_source=devto&amp;amp;utm_medium=article&amp;amp;utm_campaign=mcp_security" rel="noopener noreferrer"&gt;MCP Bridge Directory&lt;/a&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  2. Isolate Environment Variables
&lt;/h3&gt;

&lt;p&gt;Never commit &lt;code&gt;.cursorrules&lt;/code&gt; or &lt;code&gt;mcp.json&lt;/code&gt; containing plaintext API secrets into git repositories.&lt;br&gt;
&lt;em&gt;Rule:&lt;/em&gt; Utilize environment variable substitution (&lt;code&gt;"$DATABASE_URL"&lt;/code&gt;) and load secrets from local &lt;code&gt;.env.local&lt;/code&gt; files excluded via &lt;code&gt;.gitignore&lt;/code&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. Sandbox Host Filesystem Access
&lt;/h3&gt;

&lt;p&gt;Never grant MCP servers root-level read/write access to &lt;code&gt;~&lt;/code&gt; or &lt;code&gt;/&lt;/code&gt;.&lt;br&gt;
&lt;em&gt;Rule:&lt;/em&gt; Mount directories with read-only &lt;code&gt;:ro&lt;/code&gt; flags and restrict tool scopes to specific workspace subfolders.&lt;/p&gt;

&lt;h3&gt;
  
  
  4. Protect the Docker Socket
&lt;/h3&gt;

&lt;p&gt;Mounting &lt;code&gt;/var/run/docker.sock&lt;/code&gt; gives the agent root execution rights over the entire host OS.&lt;br&gt;
&lt;em&gt;Rule:&lt;/em&gt; Use a socket proxy with &lt;code&gt;POST=0&lt;/code&gt; or rootless Docker containers.&lt;/p&gt;

&lt;p&gt;Read our complete hardening checklist and configuration recipes at &lt;a href="https://mcpbridge.org/blog/mcp-security-best-practices/?utm_source=devto&amp;amp;utm_medium=article&amp;amp;utm_campaign=mcp_security" rel="noopener noreferrer"&gt;MCP Bridge Security Guide&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>security</category>
      <category>mcp</category>
      <category>ai</category>
      <category>devops</category>
    </item>
    <item>
      <title>Production Benchmarks: Stdio vs SSE Transports in the Model Context Protocol</title>
      <dc:creator>Storm</dc:creator>
      <pubDate>Mon, 14 Sep 2026 05:17:07 +0000</pubDate>
      <link>https://dev.to/stormliveai/production-benchmarks-stdio-vs-sse-transports-in-the-model-context-protocol-5cep</link>
      <guid>https://dev.to/stormliveai/production-benchmarks-stdio-vs-sse-transports-in-the-model-context-protocol-5cep</guid>
      <description>&lt;p&gt;When architecting AI agents that execute multi-step planning loops, tool invocation latency is frequently dismissed as a rounding error compared to model token generation. &lt;/p&gt;

&lt;p&gt;However, in autonomous engineering agents (like Cursor Agent or Claude Desktop executing 10 to 15 sequential queries to triage a codebase or inspect an infrastructure cluster), transport and serialization overhead compound rapidly.&lt;/p&gt;

&lt;p&gt;We benchmarked 10,000 tool executions across the two primary Model Context Protocol (MCP) transport models: Stdio and Server-Sent Events (SSE).&lt;/p&gt;

&lt;h3&gt;
  
  
  1. The Numbers: Invocation Latency
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Metric&lt;/th&gt;
&lt;th&gt;Stdio (UNIX Pipe / IPC)&lt;/th&gt;
&lt;th&gt;Remote SSE (HTTP/1.1 + TLS)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Mean Latency&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;2.1 ms&lt;/td&gt;
&lt;td&gt;19.4 ms&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;p95 Latency&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;3.8 ms&lt;/td&gt;
&lt;td&gt;32.1 ms&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;p99 Latency&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;6.2 ms&lt;/td&gt;
&lt;td&gt;48.7 ms&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Connection Setup&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;0 ms (Persistent Pipe)&lt;/td&gt;
&lt;td&gt;45 ms (TCP Handshake + TLS)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  2. Memory Footprint
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Node.js Stdio Worker:&lt;/strong&gt; ~32MB RSS per active process.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Python FastMCP Worker:&lt;/strong&gt; ~21MB RSS per process.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Compiled Go/Rust Worker:&lt;/strong&gt; &amp;lt;7MB RSS per process.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Centralized SSE Daemon:&lt;/strong&gt; ~42MB shared across all incoming client streams.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  3. Architecture Verdict
&lt;/h3&gt;

&lt;p&gt;For developer workstations and desktop agents (Claude Desktop, Cursor), &lt;strong&gt;stdio is strictly superior&lt;/strong&gt;: sub-3ms invocation, zero network port binding, and OS-supervised sandboxing.&lt;/p&gt;

&lt;p&gt;For multi-tenant cloud environments where agents share access to a centralized cluster or database, &lt;strong&gt;SSE behind an Envoy or Traefik reverse proxy&lt;/strong&gt; provides the necessary mTLS authentication and rate-limiting controls.&lt;/p&gt;

&lt;p&gt;Explore our full benchmark suite, architecture comparisons, and verified native server recipes at &lt;a href="https://mcpbridge.org/blog/scaling-mcp-servers-for-production/?utm_source=devto&amp;amp;utm_medium=article&amp;amp;utm_campaign=benchmarks_article" rel="noopener noreferrer"&gt;MCP Bridge&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>mcp</category>
      <category>performance</category>
      <category>architecture</category>
    </item>
    <item>
      <title>How to Turn Any OpenAPI Specification into an MCP Tool for Claude Desktop (In 60 Seconds)</title>
      <dc:creator>Storm</dc:creator>
      <pubDate>Sun, 13 Sep 2026 13:45:14 +0000</pubDate>
      <link>https://dev.to/stormliveai/how-to-turn-any-openapi-specification-into-an-mcp-tool-for-claude-desktop-in-60-seconds-2f07</link>
      <guid>https://dev.to/stormliveai/how-to-turn-any-openapi-specification-into-an-mcp-tool-for-claude-desktop-in-60-seconds-2f07</guid>
      <description>&lt;p&gt;The Model Context Protocol (MCP) has made it possible to connect Large Language Models directly to external environments. But if your team already has a REST API documented in OpenAPI v3 / Swagger, writing a custom FastMCP server just to test it in Claude Desktop feels like unnecessary boilerplate.&lt;/p&gt;

&lt;p&gt;In this guide, we'll look at how to convert any standard OpenAPI definition into a fully functional Claude Desktop tool in under 60 seconds without running a backend server.&lt;/p&gt;

&lt;h3&gt;
  
  
  The Architecture Problem
&lt;/h3&gt;

&lt;p&gt;OpenAPI describes HTTP endpoints, path parameters, and request bodies. Claude Desktop, on the other hand, speaks JSON-RPC 2.0 over standard input/output (&lt;code&gt;stdio&lt;/code&gt;).&lt;/p&gt;

&lt;p&gt;To bridge the two, you traditionally had to:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Write a Python or TypeScript wrapper using the MCP SDK.&lt;/li&gt;
&lt;li&gt;Manually map each OpenAPI &lt;code&gt;operationId&lt;/code&gt; to an MCP tool declaration.&lt;/li&gt;
&lt;li&gt;Define JSON Schema objects for each argument.&lt;/li&gt;
&lt;li&gt;Manage child process execution in &lt;code&gt;claude_desktop_config.json&lt;/code&gt;.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Converting In-Browser with MCP Bridge
&lt;/h3&gt;

&lt;p&gt;Instead of writing this code manually, you can use the open-source client parser at &lt;a href="https://mcpbridge.org/convert/?utm_source=devto&amp;amp;utm_medium=article&amp;amp;utm_campaign=openapi_guide" rel="noopener noreferrer"&gt;MCP Bridge&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Because the converter runs 100% in your browser using client-side JavaScript and WebAssembly, your API tokens and internal schemas never leave your computer.&lt;/p&gt;

&lt;h4&gt;
  
  
  Step 1: Export your OpenAPI Spec
&lt;/h4&gt;

&lt;p&gt;Grab your raw OpenAPI JSON or YAML URL (e.g. from Swagger UI, FastAPI, or Postman).&lt;/p&gt;

&lt;h4&gt;
  
  
  Step 2: Generate the Config
&lt;/h4&gt;

&lt;p&gt;Paste the URL into &lt;a href="https://mcpbridge.org/convert/?utm_source=devto&amp;amp;utm_medium=article&amp;amp;utm_campaign=openapi_guide" rel="noopener noreferrer"&gt;mcpbridge.org/convert&lt;/a&gt; and select &lt;strong&gt;Claude Desktop&lt;/strong&gt; as your target client.&lt;/p&gt;

&lt;h4&gt;
  
  
  Step 3: Add to Claude Desktop
&lt;/h4&gt;

&lt;p&gt;Open your configuration file:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;macOS:&lt;/strong&gt; &lt;code&gt;~/Library/Application Support/Claude/claude_desktop_config.json&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Windows:&lt;/strong&gt; &lt;code&gt;%APPDATA%\Claude\claude_desktop_config.json&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Add the generated snippet:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"mcpServers"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"my-custom-api"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"command"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"npx"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"args"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="s2"&gt;"-y"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="s2"&gt;"@modelcontextprotocol/server-openapi"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="s2"&gt;"https://api.example.com/openapi.json"&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"env"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"API_KEY"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"YOUR_SECRET_TOKEN_HERE"&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Restart Claude Desktop, and your API tools will appear under the hammer icon!&lt;/p&gt;




&lt;p&gt;&lt;em&gt;For a directory of hand-verified native MCP servers and configuration guides, check out &lt;a href="https://mcpbridge.org/?utm_source=devto&amp;amp;utm_medium=article" rel="noopener noreferrer"&gt;MCP Bridge&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>mcp</category>
      <category>webdev</category>
      <category>claude</category>
    </item>
  </channel>
</rss>
