# Revision: Cheat Sheet and Self-Check — Agent Frameworks and MCP Basics

Source: https://www.geekswithgeeks.com/en/agent-frameworks-mcp/wrap-revision

> Review the loop, protocol and safety essentials of the whole course.

## Cheat sheet

**Agent** = model + tools + loop with a step cap. **Tool call** = `tool_use` then `tool_result` matched by id. **Frameworks** save plumbing but add abstraction; keep tools independent. **MCP** = host, client, server over JSON-RPC; primitives are tools (model), resources (app), prompts (user). **FastMCP**: `@mcp.tool()`, `@mcp.resource()`, `@mcp.prompt()`. **Transports**: stdio local, streamable HTTP remote with OAuth. **Safety**: vet servers, least privilege, approvals, treat tool output as untrusted. **Quality**: clear descriptions, unit tests, evals, redacted logs.

## Questions interviewers ask

Be ready to explain: how a tool call flows between model and code, when you would skip a framework, what problem MCP solves, the difference between tools, resources and prompts, why stdout is off-limits on stdio servers, and how you would defend against prompt injection.

**Quiz:** A stdio MCP server randomly breaks. You find a `print("debug")` in a tool. What is the likely cause?

- [ ] print is slow
- [x] Stdout carries protocol messages, so prints corrupt the stream
- [ ] Python forbids print in functions
- [ ] The host does not support English

*Answer:* Stdout carries protocol messages, so prints corrupt the stream. Use standard error or a log file for diagnostics on stdio servers.

**Quiz:** Which primitive should expose a read-only company policy document?

- [ ] Tool
- [x] Resource
- [ ] Transport
- [ ] Sampling loop

*Answer:* Resource. Static reference data fits a resource that the application can attach as context.

**Quiz:** Your agent can read private files and also send HTTP requests. What is the main risk?

- [ ] Slower responses
- [x] Injected text could make it leak private data outward
- [ ] Higher disk usage
- [ ] No risk exists

*Answer:* Injected text could make it leak private data outward. Combining private-data access with an exfiltration path is dangerous; separate or gate them.
