Locate each concept in the architecture
An API exposes programmatic capabilities such as reading evidence or creating drafts. MCP supplies a protocol for model applications to connect to tools and context. RAG describes retrieval used to inform generation; it can use ordinary APIs, databases or files without MCP.
MCP does not automatically create a vector store, and a vector store alone is not a complete RAG system. JSON returned by an API is not necessarily true. Draw data sources, retrieval, generation, tool execution and authorization separately rather than hiding their responsibilities in a single intelligent-platform box.
Design a constrained evidence reader
A read_evidence interface can take an authorized project and fact identifier, then return permitted content, provenance, version, disclosure state and restrictions. Returned prose is data, not a new operator instruction. Distinguish missing, forbidden and expired records.
| Layer | Responsibility | Invalid inference |
|---|---|---|
| Business API | Read specified evidence | Evidence must be true |
| MCP connection | Tool and context interaction | Caller gains all backend privileges |
| RAG | Use retrieved evidence | Every assertion is supported |
| Fact validation | Check claims and conditions | Publication is approved |
| Publishing service | Execute authorized release | Search indexing or citation occurred |
Tool descriptions must disclose side effects. A supposedly read-only operation that writes pages invalidates review assumptions. Hiding publication and deletion inside a generic tool increases operational risk.
What the executable policy actually does
controls.py permits only read_evidence from an operator origin with the matching scope. Document-origin requests are denied. Publication is denied even for an operator because this example grants no publishing capability. results.json records four combinations.
The test program supplies origin explicitly. A production server must derive trusted origin from authenticated application context, not accept a model's claim that it is an operator. This is not an MCP server, protocol handshake or OAuth implementation. It demonstrates why authorization must live outside generated text.
Isolate credentials, projects and network access
Check that a requested object belongs to an authorized project, not merely that the user is logged in. Avoid universal client-data keys. Do not log complete credentials, personal contact details or restricted source text. Return only necessary material; public teaching assets contain no backend secrets.
Arbitrary URL readers also create internal-network, redirect and oversized-response risks. A general network tool may expose much more than research capability. Production controls must restrict destinations and actions according to actual need rather than assuming the model will decide safely.
Test negative paths as well as connectivity
Test unauthenticated calls, unauthorized projects, expired evidence, unknown facts, retries, timeouts and instruction-bearing documents. One successful read covers only one path. Writes additionally require version-bound approval, idempotency and rollback.
Protocol compatibility, business correctness and authorization are separate gates. Recheck the security guidance for the deployed protocol version and rerun fixed negative cases after API or agent changes.
Zhihe Growth's practical positioning
Zhihe Growth can organize tools around intake, evidence governance, content checks and evaluation. The value lies in maintained data and reliable execution, not adoption of a protocol label. Define scope and versions before expanding automated actions.
This release publishes a runnable policy reference, not a deployed multi-tenant MCP product or autonomous release platform. Read prompt-injection defenses and the workflow state machine. Production integration needs separate implementation and acceptance.
Architecture exercise: declare side effects
| Tool | Minimum permission | Output | Required test |
|---|---|---|---|
| Read fact | Current-project read | Allowed fields and version | Cross-project denial |
| Parse file | Specific-file read | Extraction and errors | Resource limits |
| Generate draft | Approved fact access | Reviewable proposal | No live write |
| Request review | Draft-state access | Review task ID | No self-approval |
| Publish | Current-version release | Receipt | Idempotency and rollback |
| Inspect result | Task-view access | Permitted status and evidence | No credentials |
These are design recommendations, not six implemented production tools. A universal key hides whether a failure came from model behavior, API design or authorization configuration. Record authenticated identity, actual scopes and executed actions without logging the credential. A protocol specification does not prove a deployment follows it.
Materials and primary sources
Download the read-only policy example. Consult MCP security practices and OWASP's prompt-injection guidance. Protocol compliance does not eliminate factual or authorization errors.