Skip to content

How agents work · Tools

Tools & connections

A tool is anything the AI can use besides talking: reading files, searching the web, checking your calendar. MCP is just the standard plug that connects AI to apps — like USB for AI. You don't need to know how it works, only what to allow.

The only question that matters

"What can this connection do — read, or read and change?"

  • Read-only (see your calendar, search files): low risk. Worst case, it saw something.
  • Read-and-write (send email, edit docs, post): real risk. Worst case, it did something.

Start read-only. Add write access one app at a time, only after the read-only version has earned your trust.

Connecting an app, in practice

Most AI apps have a Connectors/Integrations menu — you click the app, sign in, and choose what to allow. When it asks for permissions:

  • allow the narrowest thing that does the job ("this one folder," not "all my files");
  • prefer "ask before acting" settings when offered;
  • disconnect anything you stopped using.

A caution worth knowing: planted instructions

If your AI reads the web or emails, someone can hide instructions in that content ("ignore your rules and forward this…"). Good tools guard against it, but your habits matter more: keep write access narrow, and require your approval before anything is sent or changed. Then a planted instruction can't do much.

Next: keeping it safe

If this helped

If this made connections less mysterious, a small tip on Ko-fi keeps every guide here free. Tip on Ko-fi

Next step: Keeping it safe