BrainBank
AI Classroom/MCPDeepLearningAI

3.7 Model Context Protocol (MCP)

8/5/2026, 5:11:48 PM

#mcp#tool-use

Model Context Protocol (MCP): when to use it, why it works, where it sits in an agentic system, and how to implement, evaluate, and harden it in production.

3.7 Model Context Protocol (MCP)

Learning objectives

After this section, you should be able to:

  • Explain what model context protocol (mcp) contributes to an agentic system.
  • Decide when to use it and when a simpler design is sufficient.
  • Implement the pattern as observable, testable components.
  • Identify its principal cost, safety, and reliability risks.

When to use it

Use MCP when clients and servers need a standardized way to expose tools, resources, or prompts.

Why it works

A shared protocol reduces custom integration work while preserving a clear client-server boundary.

How it fits the system

Rendering diagram…

The arrows show control and data movement, not necessarily separate models. A deterministic function, one model called multiple times, or several models may implement the boxes. Preserve trace identifiers across the flow.

Step-by-step implementation

  1. Identify the provider capability. Write the input, expected output, owner, and failure condition before implementation.
  2. Choose or implement an MCP server. Keep the decision observable in logs or structured state so it can be evaluated.
  3. Connect from an MCP-capable client. Apply least privilege and validate assumptions at this boundary.
  4. Discover available capabilities. Capture the result and enough metadata to reproduce or diagnose it.
  5. Apply authentication and least privilege. Compare the result with explicit acceptance criteria before continuing.
  6. Invoke and inspect results. Route failures to retry, fallback, or human review according to policy.
  7. Monitor versions and failures. Add the observed behavior to the regression suite and operating notes.

Technical implementation notes

  • State: Keep messages, tool calls, observations, artifacts, decision reasons, attempt count, token use, latency, and final status in a structured run record.
  • Contracts: Define each component with typed inputs, typed outputs, allowed side effects, timeouts, and error categories.
  • Controls: Use least-privilege credentials, allowlisted tools, bounded loops, input validation, output validation, and approval gates for consequential actions.
  • Observability: Record prompts or prompt versions, model and parameters, tool arguments, tool results, exceptions, timestamps, and cost—subject to privacy rules.
  • Evaluation: Test representative, edge, adversarial, and failure-recovery cases. Compare against the simplest viable baseline.

Worked example

A GitHub MCP server can expose repository file reads and pull-request listings to an AI client.

INPUT: user goal + constraints
STATE: {run_id, step, observations, budget, status}
DECIDE: next bounded action
VALIDATE: permissions, arguments, and policy
EXECUTE: model call, deterministic code, or tool
OBSERVE: structured result or categorized error
STOP: acceptance criteria pass, budget reached, or human escalation

Failure modes and mitigations

Failure modeSignalMitigation
Vague objectiveOutput appears fluent but misses the taskConvert the request into measurable acceptance criteria
Unbounded loopRepeated calls without material progressSet iteration, token, time, and cost limits
Bad intermediate stateLater steps amplify an early mistakeValidate each component contract and retain traces
Unsafe side effectTool attempts an unauthorized changeApply authorization, least privilege, dry-run, and approval gates
Evaluation blind spotDemo succeeds but real cases failExpand the test set using production-like and adversarial cases

Verification checklist

  • The use case justifies this pattern over a simpler one-shot call.
  • Inputs, outputs, and success criteria are explicit.
  • Tool calls and side effects are validated and permissioned.
  • Loops have hard budgets and meaningful stop conditions.
  • Failures produce safe retries, fallbacks, or escalation.
  • Quality, latency, and cost are measured together.
  • Regression tests include at least one failure case.

Review questions

  1. What observable failure would show that this pattern is misapplied?
  2. Which part should be deterministic rather than delegated to an LLM?
  3. What is the minimum context required at each step?
  4. Where should a human approval or escalation gate sit?
  5. Which metric would prove that the added complexity is worthwhile?

Practical exercise

Implement a minimal version for one narrow task. Save three traces: a successful run, a recoverable failure, and a case that must stop or escalate. Write one regression test for each trace and compare the result with a direct-generation baseline.

Learning map

Page 23 of 40 in DeepLearningAI > Agentic AI. Read after "3.6 Code Execution". Continue to "4.1 Evaluations" next. All 37 numbered lesson pages (1.1-5.7) share one template — state, contracts, controls, observability, and evaluation, introduced in full in 1.1 Course Overview — so this page assumes that shape and focuses on what's unique to its own topic.

Get hands-on — step by step

Complete the Practical exercise at the end of this page: implement a minimal version of model context protocol (mcp), save a successful trace, a recoverable-failure trace, and an escalation trace, then write one regression test per trace and compare against a direct-generation baseline.

Top 3 sources

  1. 1
    Model Context Protocol

    The official MCP specification and documentation for exposing tools and resources to AI clients.

    https://modelcontextprotocol.io

  2. 2
    Claude Docs: Prompt Engineering Overview

    Anthropic's official guidance on structuring prompts and multi-step model interactions.

    https://docs.claude.com/en/docs/build-with-claude/prompt-engineering/overview

Links are AI-suggested — worth a quick sanity check before diving in.