Custom AI agents and MCP servers that do real work, safely
An agent is a model, a set of tools, and rules about when it may use them. The model is the easy part. We
design the tools, the permissions and the approval steps — the same way we built Buddy, which makes real
Google Ads changes behind a preview, confirm, execute and receipt loop.
We build agents that connect models such as Claude, GPT and Gemini to your systems through purpose-built
tools and MCP servers.
Every action that changes data goes through preview, confirmation, execution and a receipt — the loop Buddy
uses across 231 Google Ads API actions.
We design against prompt injection and excessive agency using OWASP's guidance: least-privilege credentials,
untrusted content kept separate, and human approval for high-risk actions.
Our agent work is public: a Google Ads MCP server, a Gemini CLI extension, Claude agent skills and the Buddy
agent on GitHub.
Engagements start with one workflow and a measurable outcome, not a platform.
Who this is for
Teams with a repetitive, rules-heavy task that people do today in software you already own, and a clear way to
tell whether it was done right. Good first agent projects:
Live reporting: an agent that queries your real data (ads, CRM, warehouse) and answers in
plain language with the query attached.
Operations on tools without APIs: a browser-driving agent for admin screens that can't be
automated any other way, with every step screenshotted.
CRM and data hygiene: deduplication, enrichment and field validation with a human approving
merges.
Triage: classifying and routing inbound leads, tickets or documents, with drafts for a person
to send.
Internal knowledge: answers grounded in your documentation, with sources cited.
Poor first projects: anything that spends money, emails customers or deletes data without a person approving it,
and anything described only as "an AI strategy." If a fixed script or a scheduled workflow would do the job,
we'll recommend that instead; Anthropic's own guidance on building agents makes the same point about starting
simple.
What's included in a pilot
A working agent on one workflow, used by real people on real data.
The tool catalog, each tool documented with its inputs, outputs and permission level.
An MCP server for your system where it makes sense, so the same tools work in Claude, ChatGPT, VS Code, Cursor
and other MCP clients.
Scoped credentials, stored and used in code, never pasted into a prompt.
An eval set with pass rates, so the next change is measured against a baseline.
An audit log of every tool call and every approval during the pilot.
A written recommendation: expand, change, or stop. Stopping is a legitimate outcome if the numbers say so.
How we build an agent
One workflow, one metric
Pick a task people do today, measure how long it takes and how often it goes wrong, and define what
"working" means before writing code.
Design narrow tools
Separate read tools from write tools. Each tool does one thing with validated inputs — "add negative
keywords to this campaign," not "run any query."
Scope the credentials
The agent gets its own credentials with the minimum access the workflow needs, handled in code rather than
passed to the model. User-supplied keys are encrypted at rest, as they are in Buddy.
Guard every write
Dry-run by default, a readable preview of what will change, explicit approval, execution, and a receipt in
an audit log. Spend caps and rate limits on anything that costs money.
Build an eval set
Real tasks with expected outcomes, run on every prompt or model change, plus adversarial cases that try to
make the agent misuse its tools.
Deploy and operate
Usually on Cloudflare Workers or your existing infrastructure, with logs of every tool call reviewed during
the first weeks before tools are added.
Agent mistakes we see
One all-powerful tool with full database or admin access.
No approval step on writes, because "it worked in the demo."
No eval set, so nobody notices when a model update changes behavior.
An inbox-reading agent that can also send email on its own.
API keys pasted into prompts or stored in plain text.
An MCP server that passes the user's token straight through to a downstream API.
Tool results returned as huge raw payloads, so the model loses the instruction it was following.
Success measured in conversations rather than outcomes.
What we mean by an AI agent, and where MCP fits
A chatbot answers questions. An agent takes steps: it reads data, decides what to do next, calls a tool, checks
the result, and repeats until the job is done or it needs a human. That loop of reasoning and acting is the
pattern described in the
ReAct paper, and it needs four
things beyond the model: tools with clear inputs and outputs, credentials scoped to what the job needs, context
about your business, and guardrails on anything that changes data or talks to customers.
The
Model Context Protocol
(MCP) is the open standard for the tools part. It defines how AI applications connect to external systems, and
the project lists support in Claude, ChatGPT, Visual Studio Code, Cursor and others. Build an MCP server for
your system once and it works in each of them, which is why most of our tool work ships as MCP servers. Remote
MCP servers authenticate users through the OAuth-based flow in the
MCP authorization specification, so the agent never handles a raw password.
Security: prompt injection and excessive agency
OWASP lists prompt injection first in its
Top 10 for LLM applications. Direct injection comes from what a user types; indirect injection comes from content the agent reads — a web
page, a file, an email — that contains instructions. Researchers demonstrated the indirect form against real
LLM-integrated apps in 2023, and OWASP is candid that it's unclear whether fool-proof prevention exists. The
related risk OWASP calls
excessive agency
has three root causes: excessive functionality, excessive permissions and excessive autonomy. Our design rules
map to those directly.
Risk
What we do about it
Excessive functionality
Narrow, single-purpose tools; no generic "run SQL" or "call any URL" tool
Excessive permissions
The agent's own least-privilege credentials, held in code; read and write split into separate tools
Excessive autonomy
Human approval for anything irreversible, costly or customer-facing; spend caps and rate limits
Indirect prompt injection
Untrusted content clearly separated and treated as data; an agent that reads it never holds write
credentials in the same context
Malformed or unsafe output
Output formats validated in deterministic code before any tool runs
MCP-specific attacks
No token passthrough, per-client consent, and the other mitigations in MCP's
security best practices
Silent regressions
Adversarial eval cases run on every prompt or model change
A useful test from Simon Willison's writing: if one agent has access to private data, reads untrusted content
and can send data out, it can be tricked into leaking. We break at least one of those three links in every
design.
Model choice
We're model-agnostic. Our open-source Python agent supports Claude, GPT and Gemini, and Buddy lets users bring
their own keys. We choose per task on tool-use reliability, latency and cost, and the eval set makes switching
models a measured decision rather than a guess. Repeated trials matter: benchmarks such as
τ-bench show agents that pass a
task once can fail it on the next attempt, so we report pass rates across runs, not a single demo.
Pricing and engagement
A short discovery to pick the workflow and define success, a fixed-scope pilot, then production hardening. After
launch, either handoff or an ongoing retainer, as with our other
app work. Model and hosting costs are billed by the providers to your
accounts. Client agents and MCP servers are your IP; we open-source components only when you choose to. Nothing
is billed as a percentage of spend; the terms are on our pricing page.
Platforms we work in
Models, protocols and infrastructure we build agents on.
Our conversational Google Ads agent: 231 API actions (93 read queries, 138 write mutations) behind a 55-tool
catalog, with every write running through preview, confirm, execute and receipt. It runs on the web and in
our iOS and Android apps.
A Python MCP server giving any MCP client live Google Ads API access. At launch it had 29 tools — 9 read, 7
audit, 11 write, 2 documentation — with every write tool dry-run by default.
A Gemini CLI extension with MCP tools, custom commands, agent skills, credentials stored in the system
keychain, and hooks that block unconfirmed writes and keep an audit trail.
77 reusable agent skills, 2 MCP servers and 7 commands for managing Google Ads from Claude and Gemini CLI,
published under the itallstartedwithaidea organization.
An agent with a browser bridge edited CRM workflows in a builder with no public API, then verified fourteen
published workflows against their execution logs before anyone declared the migration done.
A 104M-parameter advertising model trained from blank weights on a single GPU in 28 minutes for $0.13 of
cloud compute, bundled with 14 MCP connectors and a skills framework. Apache 2.0.
MCP, the Model Context Protocol, is an open standard for connecting AI applications to external systems. An
MCP server exposes your system's actions as tools any compatible client — Claude, ChatGPT, VS Code, Cursor —
can use. You need one if you want AI tools to work with your data without building a separate integration for
each.
Which AI model do you use?
Whichever performs best on your eval set for the cost and latency you can accept. We build model-agnostic; our
open-source agent supports Claude, GPT and Gemini.
How do you stop an agent from doing something harmful?
Narrow tools, least-privilege credentials handled in code, dry-run previews, human approval on high-risk
actions, audit logs, spend caps and adversarial testing — following OWASP's guidance on prompt injection and
excessive agency.
Can prompt injection be fully prevented?
Not reliably, and OWASP says so. That's why we design so a successful injection can't do much: the agent
reading untrusted content has no write access, irreversible actions wait for a person, and every tool call is
logged.
Can an agent work with software that has no API?
Yes, through a browser bridge that drives the admin interface and screenshots every step. We used this to edit
CRM workflows in a builder with no public API during the Squeaky Clean Turf migration.
How do you know if the agent is working?
An eval set of real tasks with expected outcomes, run on every change, plus production logs of every tool call
and the business metric we agreed at the start.
Will you open-source the agent you build for us?
Only if you want to. Client work is your IP by default. We do bring our own open-source components into builds
to save time.
Tell us about the workflow
Describe the task you'd like an agent to take on, the systems it touches, and how you'd measure success.
John, Kristy, or Sandeep will reply.One of the three of us will respond personally within 1 business day. No SDR queue.
Message received.
One of us will reply directly within one business day. While you wait, run a free
Buddy audit on your account.
Top 25 references
The primary sources, standards, research, and tools we rely on for this work. Every link was checked on
2026-10-11. We aren't affiliated with these publishers unless noted.
Official documentation
What is the Model Context Protocol (MCP)?— Model Context Protocol The project's own overview, listing support in Claude, ChatGPT, VS Code, Cursor and other
clients.
Security Best Practices— Model Context Protocol Known MCP attack patterns, such as confused-deputy and token passthrough, with the mitigations the spec
expects.
Tool use with Claude— Claude Platform Docs (Anthropic) How Claude decides to call tools, how tool schemas are defined and how results are returned.
Function calling— OpenAI API Docs OpenAI's tool-calling interface, including strict schemas that keep arguments valid.
Introduction to function calling— Google Cloud Documentation Gemini's function-calling model on Google Cloud, useful when comparing tool reliability across
vendors.
Cloudflare Agents— Cloudflare Docs The Agents SDK for stateful agents on Workers and Durable Objects, the runtime we usually deploy to.
Build a remote MCP server— Cloudflare Docs Step-by-step deployment of an authenticated MCP server that any remote MCP client can reach.
Standards & policy
MCP Specification (2026-07-28)— Model Context Protocol The current protocol specification for tools, resources, prompts and transports.
MCP Authorization— Model Context Protocol How remote MCP servers use OAuth so agents never handle a user's raw credentials.
LLM01:2025 Prompt Injection— OWASP Gen AI Security Project Defines direct and indirect prompt injection and lists the layered mitigations we design to.
LLM06:2025 Excessive Agency— OWASP Gen AI Security Project Names the three root causes (excessive functionality, permissions and autonomy) that narrow tools are meant
to prevent.
OWASP Top 10 for LLM Applications— OWASP Gen AI Security Project The full list of LLM application risks, from sensitive data disclosure to unbounded consumption.
AI Risk Management Framework— NIST The U.S. government framework for governing, mapping, measuring and managing AI risk in an
organization.
NIST AI 600-1: Generative AI Profile— NIST Applies the AI RMF to generative AI, with specific actions for information security and human
oversight.
MITRE ATLAS— MITRE A knowledge base of real adversary tactics against AI systems, useful for writing adversarial eval
cases.
Defeating prompt injections by design (CaMeL)— arXiv (Debenedetti et al., Google DeepMind) Separates trusted control flow from untrusted data, the same principle as keeping write credentials away
from untrusted content.
Expert guides
Building effective agents— Anthropic Engineering Anthropic's argument for simple, composable workflows over complex frameworks, and when a true agent
is warranted.
Writing effective tools for agents— Anthropic Engineering Practical advice on tool naming, scope, response size and evaluation that matches how we design tool
catalogs.
A practical guide to building agents— OpenAI OpenAI's guide to picking agent use cases, designing tools and layering guardrails with human
intervention.
The lethal trifecta for AI agents— Simon Willison Why an agent with private data, untrusted content and an outbound channel at once is exploitable.
Communities & courses
Model Context Protocol servers— GitHub (modelcontextprotocol) Reference MCP server implementations and a directory of community servers to learn from before building
your own.
AI disclosure: This page was drafted with AI assistance and edited by a human. Third-party facts
link to the official source they came from (checked 2026-10-11); platform names and logos belong to their owners
and do not imply a partnership or endorsement.