<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>VerifyMCP blog</title><description>Independent analysis of Model Context Protocol server security and the MCP ecosystem.</description><link>https://verifymcp.io</link><atom:link href="https://verifymcp.io/rss.xml" rel="self" type="application/rss+xml"/><item><title>MCP vs RAG: how retrieval fits behind the protocol</title><link>https://verifymcp.io/blog/mcp-vs-rag</link><guid isPermaLink="true">https://verifymcp.io/blog/mcp-vs-rag</guid><description>RAG is a pattern for getting relevant text into a model&apos;s context. MCP is a protocol for tools and resources. One can serve the other. Here is how to choose.</description><pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate><category>mcp</category><category>rag</category><category>security</category></item><item><title>MCP vs API: what changes when the caller is a model</title><link>https://verifymcp.io/blog/mcp-vs-api</link><guid isPermaLink="true">https://verifymcp.io/blog/mcp-vs-api</guid><description>MCP does not replace your API, it usually wraps one. What actually differs under the stateless 2026-07-28 spec, and what wrapping costs you in security.</description><pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate><category>mcp</category><category>api</category></item><item><title>MCP vs Skills: where the trust boundary sits</title><link>https://verifymcp.io/blog/mcp-vs-skills</link><guid isPermaLink="true">https://verifymcp.io/blog/mcp-vs-skills</guid><description>Agent Skills run inside your own agent&apos;s sandbox; an MCP server is a third-party dependency on the wire. How to choose by trust boundary and blast radius.</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate><category>mcp</category><category>skills</category><category>security</category></item><item><title>MCP security best practices: the 2026 checklist</title><link>https://verifymcp.io/blog/mcp-security-best-practices</link><guid isPermaLink="true">https://verifymcp.io/blog/mcp-security-best-practices</guid><description>The MCP security considerations that matter, as two checklists covering remote endpoints and packaged servers. Every check has a command and a pass condition.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>guides</category><category>security</category><category>mcp</category></item><item><title>VerifyMCP now supports MCP 2026-07-28</title><link>https://verifymcp.io/blog/mcp-2026-07-28-support</link><guid isPermaLink="true">https://verifymcp.io/blog/mcp-2026-07-28-support</guid><description>The 2026-07-28 revision makes MCP stateless, removing the initialize handshake and sessions. What changed, what it means for your server, and which scores move.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate><category>mcp</category><category>spec</category><category>scoring</category></item><item><title>Why MCP server security is hard, and how we score it</title><link>https://verifymcp.io/blog/mcp-server-security</link><guid isPermaLink="true">https://verifymcp.io/blog/mcp-server-security</guid><description>MCP servers give agents the power to run code and call tools, which makes server trust a security problem. The threat model, and how we turn it into a number.</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>security</category><category>mcp</category></item></channel></rss>