Blog

Updates, insights, and MCP know-how from the team at Stacklok

May 13, 2026

Optimizing multi-MCP workflows

Managing dozens of MCP servers at scale creates real costs. Learn how a layered gateway, optimizer, and composite tools keep complexity under control.

May 11, 2026

MCP server governance starts with discovery

When MCP server URLs live in Slack threads, nobody knows what’s approved. See how Stacklok’s Registry Server solves discovery and access control at scale.

May 07, 2026

Enforcing MCP tool annotation policies with Cedar

MCP tool annotations declare what a tool does. Here’s how to enforce Cedar policies against those declarations using Stacklok’s ToolHive Kubernetes operator.

May 06, 2026

Inside Dockyard: How Stacklok + Cisco AI Defense are securing MCP servers and skills

Stop shipping unscanned MCP servers and hoping for the best. Dockyard gives every server signatures, SBOMs, and security scans before it reaches your agents.

May 05, 2026

How to evaluate MCP runtimes against the OWASP Top 10

The OWASP MCP Top 10 reads like ten distinct problems, and most coverage treats them that way: ten boxes to check, ten features to ship. Token mismanagement, tool poisoning, and …

May 04, 2026

Shadow MCP: the AI governance problem hiding in plain sight

Most enterprises believe they have a handle on their MCP deployments. They’re usually wrong, and often by an order of magnitude. Here’s what you’ll learn in this post: The number …