mcp.json Security: A Worm Now Hunts Your Claude Config

A npm worm now hunts ~/.claude/mcp.json by name. Here is a hands-on mcp.json security pass — env indirection, scoping, and 4 checks I ran today.
I Tested Claude Code Memory vs mem0. One Stores Files, One Stores Opinions.

I stored 10 detailed memories in mem0 and got back 15 atomic facts. Here is what survived, what did not, and when each system matters.
I Thought Deploying an MCP Server to Azure Would Be Simple. Three Port Conflicts Later…

FastMCP worked locally. Docker ran fine. Then Azure deployment hit port conflicts, auth failures, and container issues. Here is how I fixed all of it.
Agent Builder Was Supposed to Make This Easy. It Didn’t.

Three bugs killed my agent build. The visual workflow builder did not stop any of them. Here is my honest review of OpenAI Agent Builder.
I Forked a Repo to Supercharge Claude Code (And Accidentally Learned Zero-Trust Architecture)

I forked a repo to extend Claude Code and accidentally learned zero-trust architecture. Here is what happened when the tool outgrew its tooling.
I Spent 2 Days with AWS AgentCore and Finally Understood Their Agent Strategy

I spent 2 days with AWS AgentCore after its NY Summit launch. Bedrock Agents is just the surface. AgentCore is the real infrastructure layer.