Urgent.News

What's breaking now, across thousands of outlets.

Tech

Building a Zero-Dependency MCP Server with 22 Security Layers in Go

The Model Context Protocol (MCP) is becoming the standard for AI-tool integration. Claude Desktop, Cursor, Windsurf — they all use it. The protocol is well-designed. The official SDKs give you transport, routing, and session management. What they don't give you is security. This post is the technical deep-dive into AegisGate MCP — a standalone MCP server framework with 22 security layers, zero…

The Model Context Protocol (MCP) is a widely adopted standard for integrating AI tools, utilized by applications such as Claude Desktop, Cursor, and Windsurf. While the protocol itself is well-designed, with official SDKs providing transport, routing, and session management, it lacks built-in security features. This article delves into AegisGate MCP, a standalone MCP server framework that offers 22 security layers, zero external Go dependencies, and a fully vendor neural ML inference pipeline.

The primary constraint was achieving zero external Go module dependencies. This decision was driven by two key factors: enabling air-gapped deployment, where developers can build the server on a machine without network access, and reducing the supply chain attack surface by eliminating transitive dependencies that could introduce CVEs. Consequently, every component — from HTTP routing to JSON-RPC handling and model inference — is implemented in-house or sourced from vendor binaries.

One of the most challenging aspects of maintaining zero dependencies was implementing the neural machine learning inference pipeline. The team chose to vendor the ONNX Runtime shared libraries directly to avoid introducing additional dependencies during runtime. The model, a CharCNN-BiLSTM neural network with approximately 1.6 million parameters, is used for detecting adversarial prompt injection.

At build time, developers can choose between a static binary with heuristic-only detection or a version that links against the vendored ONNX Runtime for the full neural network inference capabilities.

The server adheres to the Streamable HTTP transport defined in MCP 2025-06-18, supporting both JSON-RPC 2.0 over HTTP POST and optional Server-Sent Events (SSE) streaming. It manages sessions using the Mcp-Session-Id header, with sessions lasting 30 minutes by default. The server creates new sessions upon an initialize request and validates existing sessions on subsequent requests, issuing a 404 status for invalid or expired sessions rather than the more conventional 401.

This architecture offers a robust, secure, and self-contained solution for AI tool integration, eliminating the need for external dependencies while providing the flexibility to enable or disable the advanced ML inference pipeline at build time.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Custom Functions in CSS

CSS already has plenty of useful functions, like calc() , min() , max() , and clamp() . They let you build more flexible styles without repeating the same logic.

  • CSS already has functions like calc(), min(), max(), and clamp()
  • @function at-rule defines custom functions with parameters and results
  • Custom functions can accept multiple parameters, type declarations, and defaults

My barcode generator encoded whatever I gave it — the check digit is the scanner's only trust

Two months ago I added barcode symbologies to what had been a plain QR endpoint — code128, EAN-13, UPC-A. My test suite verified the images rendered and that my phone could decode them.

  • Author expanded QR code endpoint to support barcode symbologies
  • Partner scanned EAN-13 labels with handheld laser scanner, received invalid read error
  • Author implemented fix with rules for twelve-digit UPC-A codes and check digit validation

More from Thursday 8 October →