Memory hook: Tools grant capability; policy sets limits.
Must remember
- Coding agents such as Antigravity and supported third-party agents can inspect repositories, propose patches and run tools. Give them a scoped workspace and explicit task boundaries.
- MCP exposes tool/resource interfaces; skills, rules, plugins, hooks and subagents customize workflows. Review each integration’s permissions and data access rather than trusting its name.
- Use isolated development environments such as Cloud Workstations or appropriately configured GKE sandboxes. Limit network egress, secrets, filesystem access and privileged execution.
- Ask agents to produce reviewable changes with meaningful tests, dependency checks and static analysis. Generated tests can mirror a bug, so inspect the intended behavior independently.
- Agent-assisted refactoring, performance tuning and vulnerability remediation need measured before/after evidence. Do not let a tool claim replace build or runtime validation.
- Agents CLI and registries can help manage supported enterprise agent workflows. Distinguish human-operated administrative actions from delegated agent operations and audit both.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| An agent needs to inspect a private repository | Scoped repository access in an isolated environment. |
| A plugin requests deployment credentials for linting | Reduce or reject the unnecessary capability. |
Traps
- A sandbox with broad mounted credentials is not effectively isolated.
- More parallel agents do not guarantee correct integration or lower total cost.
Active recall
1. What does MCP standardize?
A way to expose tools/context to clients; it does not independently authorize every action.
2. Why review generated tests?
They may assert the implementation’s current behavior rather than the required behavior.
3. How verify a performance patch?
Use representative benchmarks and check correctness, resource use and regressions.
4. Why separate deployment from editing rights?
A code-generation mistake should not automatically become a production change.
5. What should tool audit logs record?
Identity, requested action, target, authorization outcome and result without leaking secrets.