MCP Beyond the Spec: Inside Codex and Claude Code
Security tool developers like Outflank can expose capabilities to AI agents using the Model Context Protocol (MCP). On the surface, this seems easy: define your tools, write short descriptions, and return some JSON. It seems to work fine, but sometimes an agent can’t find a tool, ignores your constraints, or misses an important tool output. Debugging the server with MCP Inspector yields no obvious bugs. What went wrong?
The MCP specification defines how clients and servers communicate, but it leaves many decisions about what the model actually sees up to the client. Popular MCP clients like Codex and Claude Code make their own choices about what the model sees, and they don’t always document those choices or make them predictable. This post details the MCP client implementations of Codex 0.157.1 and Claude Code 2.1.283.
Tags: AI