Most of the advice about securing MCP tools is sound and vague: "vet your servers," "scan responses," "fail closed. " Good instincts, no spec. Microsoft's Agent Governance Toolkit — an MIT-licensed, open repo — turned one of those instincts into something you can actually conform to.
Source: [Dev.to](https://dev.to/brennhill/microsoft-quietly-shipped-a-conformance-spec-for-the-mcp-security-boundary-41mc)