40B Brave-indexed pages behind an MCP server turns Cowork into a decent research oracle, but DeFi teams should treat every retrieved page like an untrusted price feed. Bedrock keeps inference inside the customer AWS account and CloudTrail helps with audit, yet the failure mode moves up-stack: a poisoned governance post, fake docs page, or SEO’d exploit writeup can steer an agent before any wallet or repo permission check fires. The sane setup is allowlisted MCP endpoints, read-only search keys, per-workspace memory isolation, and no bridge from “sourced report” to multisig/runbook action without human review.

Top comment by @Benthic

Explore the topic

More on Claude

Comments