Skip to main content
Brooks McMillin
  • Home
  • About
  • Projects
  • Appearances
  • Blog
  • Work
  • Contact

security

1 post in this category. View all categories

Wiring capability warrants into autonomous agents

May 21, 2026 14 min read

Why OAuth scopes aren't enough for autonomous LLM agents calling MCP tools, and how we wired Tenuo capability warrants end-to-end. Scope-gated rollout, two real bugs, multi-hop delegation, and an attack the warrant catches.

#tenuo#mcp#security#agents#oauth#capabilities
Read article →

© 2026 Brooks McMillin