<?xml version="1.0" encoding="utf-8"?>
<!--
  Atom feed for norviq.dev/blog. Hand-maintained — there is no build step on this site.
  Add one <entry> per post, newest first, and update <updated> at the feed level to match.
-->
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Norviq blog</title>
  <subtitle>Notes on runtime security for LLM agent tool calls.</subtitle>
  <link href="https://norviq.dev/blog/feed.xml" rel="self"/>
  <link href="https://norviq.dev/blog/"/>
  <id>https://norviq.dev/blog/</id>
  <updated>2026-08-24T00:00:00Z</updated>
  <author><name>Santosh Kumar Puppala</name></author>
  <!-- ENTRIES:BEGIN -->
    <entry>
      <title>The MCP server you approved is not the one running tomorrow</title>
      <link href="https://norviq.dev/blog/the-mcp-server-you-approved/"/>
      <id>https://norviq.dev/blog/the-mcp-server-you-approved/</id>
      <updated>2026-08-24T00:00:00Z</updated>
      <summary>A tool definition is an answer, not an artifact — and the protocol has a blessed way for a server to change its answer after you approved it. What that opens, what closes it, and where every defence I know of, mine included, gets thin.</summary>
    </entry>
    <!-- ENTRIES:END -->

</feed>
