Andrew Stellman ๐Ÿ‘พ

@andrewstellman
240 Followers
197 Following
590 Posts
Developer, team lead, musician. Author of O'Reilly Media books including Head First C#, Learning Agile, and Head First PMP. Solving complexity with simplicity.
Websitehttps://www.stellman-greene.com
Twitterhttps://twitter.com/AndrewStellman
LinkedInhttps://www.linkedin.com/in/andrewstellman
GitHubhttps://github.com/andrewstellman/
I break this down in my latest Oโ€™Reilly Radar piece:
๐Ÿ‘‰ https://www.oreilly.com/radar/mcp-introduces-deep-integration-and-serious-security-concerns/
MCP Introduces Deep Integration--and Serious Security Concerns

MCPโ€”the Model Context Protocol introduced by Anthropic in November 2024โ€”is an open standard for connecting AI assistants to data sources and development

Oโ€™Reilly Media

MCP basically wires your AI assistant straight into your dev environment. It sends files, code snippets, even whatever you just highlightedโ€”automatically.

Itโ€™s really useful.

But if youโ€™re in a regulated industry, it can be a compliance nightmare.

That snippet Copilot just shipped off might include patient data, API keys, or VPN infoโ€ฆ and now itโ€™s outside your network. Itโ€™s an interesting time to be in securityโ€”Iโ€™m sure red teams are having a field day with this.

In my latest Oโ€™Reilly Radar piece, I dig into:

โžก๏ธ ๐™’๐™๐™ฎ this deep integration is so powerful for developers

โžก๏ธ ๐™’๐™๐™š๐™ง๐™š it creates massive security and compliance risks

โžก๏ธ ๐™’๐™๐™–๐™ฉ enterprises are already doing to adapt

Until we build better guardrails, MCP puts organizations in a tough spot: boost AI productivity, or lock things down for security.

๐Ÿ“– Read the article here:
๐Ÿ‘‰ https://www.oreilly.com/radar/mcp-introduces-deep-integration-and-serious-security-concerns/

MCP Introduces Deep Integration--and Serious Security Concerns

MCPโ€”the Model Context Protocol introduced by Anthropic in November 2024โ€”is an open standard for connecting AI assistants to data sources and development

Oโ€™Reilly Media

๐Ÿšจ ๐Œ๐‚๐: ๐“๐ก๐ž ๐ง๐ž๐ฐ ๐ฉ๐ซ๐จ๐๐ฎ๐œ๐ญ๐ข๐ฏ๐ข๐ญ๐ฒ ๐›๐จ๐จ๐ฌ๐ญ ๐ญ๐ก๐š๐ญ ๐œ๐จ๐ฎ๐ฅ๐ ๐›๐ซ๐ž๐š๐ค ๐ฒ๐จ๐ฎ๐ซ ๐œ๐จ๐ฆ๐ฉ๐ฅ๐ข๐š๐ง๐œ๐ž ๐Ÿšจ

MCPโ€”the Model Context Protocolโ€”plugs AI assistants directly into your environment. Your open files, your editor selections, even the last thing you typed.

Thatโ€™s great for productivity. But when all of that gets transmitted upstream to remote servers? You may have just leaked internal URLs, config files, or test data with real user info.

Weโ€™ll dig into how to take control of that process so the AI is working for you, not the other way around.

โœ… Attend free with a 10-day Oโ€™Reilly trial
โœ… Or check if your company already pays for access

See you tomorrow. Letโ€™s make these tools work for you.

โ€ฆitโ€™s about how you actually use these tools in your day-to-day work, when you need to get real code written.

Weโ€™ll talk about ๐™๐™ค๐™ฌ ๐˜พ๐™๐™–๐™ฉ๐™‚๐™‹๐™ ๐™–๐™ฃ๐™™ ๐™ก๐™–๐™ฃ๐™œ๐™ช๐™–๐™œ๐™š ๐™ข๐™ค๐™™๐™š๐™ก๐™จ ๐™ง๐™š๐™–๐™ก๐™ก๐™ฎ ๐™ฌ๐™ค๐™ง๐™ , and how knowing that changes the way you prompt Copilot.

Your code is part of that prompt. The names you use, the structure, what you just editedโ€”Copilot is looking at all of it when it makes suggestions.

๐Ÿšจ ๐Œ๐ฒ ๐Ž'๐‘๐ž๐ข๐ฅ๐ฅ๐ฒ ๐‹๐ข๐ฏ๐ž ๐“๐ซ๐š๐ข๐ง๐ข๐ง๐  ๐œ๐จ๐ฎ๐ซ๐ฌ๐ž ๐จ๐ง ๐ฎ๐ฌ๐ข๐ง๐  ๐€๐ˆ ๐Ÿ๐จ๐ซ ๐๐ž๐ฏ๐ž๐ฅ๐จ๐ฉ๐ฆ๐ž๐ง๐ญ ๐ฌ๐ญ๐š๐ซ๐ญ๐ฌ ๐ข๐ง ๐จ๐ง๐ž ๐ก๐จ๐ฎ๐ซ! ๐Ÿšจ

โœจ You can still attend for free! Details below.

Copilot and ChatGPT for Java and C# Developers
๐Ÿ“… Live April 16
๐Ÿ”— https://learning.oreilly.com/live-events/copilot-and-chatgpt-for-java-and-c-developers/0642572004454/

This is about ๐ซ๐ž๐š๐ฅ ๐๐ž๐ฏ๐ž๐ฅ๐จ๐ฉ๐ฆ๐ž๐ง๐ญ ๐ฐ๐ข๐ญ๐ก ๐€ I. It's not just showing off a bunch of cool Copilot tricksโ€ฆ

Weโ€™ll explore all of that, and moreโ€”how to guide AI, shape the output, and make sure itโ€™s helping you write code youโ€™re proud of.

โœ… Attend free with a 10-day Oโ€™Reilly trial
โœ… Or check if your company already pays for access

See you tomorrow. Letโ€™s make these tools work for you.

Weโ€™ll dig into ๐™๐™ค๐™ฌ ๐˜พ๐™๐™–๐™ฉ๐™‚๐™‹๐™ ๐™–๐™ฃ๐™™ ๐™ก๐™–๐™ฃ๐™œ๐™ช๐™–๐™œ๐™š ๐™ข๐™ค๐™™๐™š๐™ก๐™จ ๐™ง๐™š๐™–๐™ก๐™ก๐™ฎ ๐™ฌ๐™ค๐™ง๐™ , and how you can use that deeper understanding to get the most out of GitHub Copilot.

Because your code is the prompt. Your names, structure, and recent edits all influence Copilotโ€™s suggestions.

๐Ÿšจ ๐‹๐š๐ฌ๐ญ ๐œ๐ก๐š๐ง๐œ๐ž! ๐Œ๐ฒ ๐Ž'๐‘๐ž๐ข๐ฅ๐ฅ๐ฒ ๐‹๐ข๐ฏ๐ž ๐“๐ซ๐š๐ข๐ง๐ข๐ง๐  ๐œ๐จ๐ฎ๐ซ๐ฌ๐ž ๐ข๐ฌ ๐ญ๐จ๐ฆ๐จ๐ซ๐ซ๐จ๐ฐ ๐Ÿšจ

โœจ You can still attend for free! Details below.

Copilot and ChatGPT for Java and C# Developers
๐Ÿ“… Live April 16
๐Ÿ”— https://learning.oreilly.com/live-events/copilot-and-chatgpt-for-java-and-c-developers/0642572004454/

This isnโ€™t just about cool demos or showing off AI tricks. Itโ€™s about learning how to actually use these tools every dayโ€”to write better code, faster.