What 1,137 agent writes taught this MCP server author about tool scoping and safety

QuanTradin · reddit · 2026-09-04

The author of a production MCP server managing a paper trading desk (22 tools) shared audit-ledger lessons: since Aug 19 agents made 1,137 writes, deployed 781 bots, and lost $1.34M in paper money — 773 of the 781 never called the backtest tool first, proving agents skip optional tools.

Controls that held:

Two mistakes admitted: the ledger only records successful writes (403s raise before logging), so there's no record of attempts; and zero of 33 minted keys used the safe backtest-only default. Works via Claude Code and Claude Desktop (mcp-remote); the claude.ai web and API MCP connectors are OAuth-only and unsupported.

Original post →

More from coding & agent

coding & agent channel →