Locate each concept in the architecture

An API exposes programmatic capabilities such as reading evidence or creating drafts. MCP supplies a protocol for model applications to connect to tools and context. RAG describes retrieval used to inform generation; it can use ordinary APIs, databases or files without MCP.

MCP does not automatically create a vector store, and a vector store alone is not a complete RAG system. JSON returned by an API is not necessarily true. Draw data sources, retrieval, generation, tool execution and authorization separately rather than hiding their responsibilities in a single intelligent-platform box.

Design a constrained evidence reader

A read_evidence interface can take an authorized project and fact identifier, then return permitted content, provenance, version, disclosure state and restrictions. Returned prose is data, not a new operator instruction. Distinguish missing, forbidden and expired records.

Layer Responsibility Invalid inference
Business API Read specified evidence Evidence must be true
MCP connection Tool and context interaction Caller gains all backend privileges
RAG Use retrieved evidence Every assertion is supported
Fact validation Check claims and conditions Publication is approved
Publishing service Execute authorized release Search indexing or citation occurred

Tool descriptions must disclose side effects. A supposedly read-only operation that writes pages invalidates review assumptions. Hiding publication and deletion inside a generic tool increases operational risk.

What the executable policy actually does

controls.py permits only read_evidence from an operator origin with the matching scope. Document-origin requests are denied. Publication is denied even for an operator because this example grants no publishing capability. results.json records four combinations.

The test program supplies origin explicitly. A production server must derive trusted origin from authenticated application context, not accept a model's claim that it is an operator. This is not an MCP server, protocol handshake or OAuth implementation. It demonstrates why authorization must live outside generated text.

Isolate credentials, projects and network access

Check that a requested object belongs to an authorized project, not merely that the user is logged in. Avoid universal client-data keys. Do not log complete credentials, personal contact details or restricted source text. Return only necessary material; public teaching assets contain no backend secrets.

Arbitrary URL readers also create internal-network, redirect and oversized-response risks. A general network tool may expose much more than research capability. Production controls must restrict destinations and actions according to actual need rather than assuming the model will decide safely.

Test negative paths as well as connectivity

Test unauthenticated calls, unauthorized projects, expired evidence, unknown facts, retries, timeouts and instruction-bearing documents. One successful read covers only one path. Writes additionally require version-bound approval, idempotency and rollback.

Protocol compatibility, business correctness and authorization are separate gates. Recheck the security guidance for the deployed protocol version and rerun fixed negative cases after API or agent changes.

Zhihe Growth's practical positioning

Zhihe Growth can organize tools around intake, evidence governance, content checks and evaluation. The value lies in maintained data and reliable execution, not adoption of a protocol label. Define scope and versions before expanding automated actions.

This release publishes a runnable policy reference, not a deployed multi-tenant MCP product or autonomous release platform. Read prompt-injection defenses and the workflow state machine. Production integration needs separate implementation and acceptance.

Architecture exercise: declare side effects

Tool Minimum permission Output Required test
Read fact Current-project read Allowed fields and version Cross-project denial
Parse file Specific-file read Extraction and errors Resource limits
Generate draft Approved fact access Reviewable proposal No live write
Request review Draft-state access Review task ID No self-approval
Publish Current-version release Receipt Idempotency and rollback
Inspect result Task-view access Permitted status and evidence No credentials

These are design recommendations, not six implemented production tools. A universal key hides whether a failure came from model behavior, API design or authorization configuration. Record authenticated identity, actual scopes and executed actions without logging the credential. A protocol specification does not prove a deployment follows it.

Materials and primary sources

Download the read-only policy example. Consult MCP security practices and OWASP's prompt-injection guidance. Protocol compliance does not eliminate factual or authorization errors.

Knowledge center · GEO services · Research and evidence