Lesson 23 of 30, Module 3: Make It Trustworthy. It refuses to leave the folder, asks before it overwrites, and remembers your answers.
What you can do after this lesson
A rule that must always hold has to live in the thing you own, not in the app that happens to ask about it. Then attack it on purpose, because a guard you have never attacked is only a guess.
The problem we inherited
A server that can write can write over the wrong document, and there is no undo you can reach from a chat.
Code in this lesson
Every block the lesson shows on screen, in the order it appears.
1. Write the plain Python function
2. Put the @mcp line above it
3. Write the one-line docstring
4. Restart Claude Desktop
5. Ask Claude to use it
Downloads
- Module 3 checkpoint (scribe-checkpoint-m3.zip): working code as the module leaves it, so a broken session costs you nothing
- The course GitHub repo: every checkpoint, the README and the full lesson list
Prefer to read?
The written version of this part of the course is on Substack: https://genaiunplugged.substack.com/p/give-your-ai-agents-memory-mcp-shared.
Lesson transcript
What changed in module 3
When this module began, your server did whatever it was told. Today it stays in its folder, it asks first, and it remembers.
Hello, and welcome to lesson 23 of the MCP Masterclass. This lesson is a quick recap of everything we built in module 3. And we start with our map, as always.
13 lit boxes. The guard sits between edit_doc and your documents, and the memory sits beside it. 3 boxes are still dark, and all 3 are module 4.
Well, there is nothing new in this lesson. 5 points, and then module 4.
The 5 points to remember
Point number 1. The asking belongs to the host, until you own it.
Claude Desktop asks before a tool runs, and 1 click on Always allow switches that off. A question that must always be asked has to live inside your server, because that is the only thing that travels to every app.
Point number 2. The guard is 3 small jobs, not 1 big one.
A fence, so Scribe stays inside your folder. A wrapper, so every refusal from Google comes back as a sentence. And a question on the argument, so Scribe asks before it writes. A form where the app can show one, and a sentence where it cannot.
Point number 3. A guard is only a guard once you have attacked it.
A path, an empty find, a no, and Google. Four refusals, four plain sentences, and the draft untouched every time. Run break_it.py after every change you make to the server.
Point number 4. A chat is where the words live, and the words do not leave the chat.
So the rules live in a file next to your server. Remember writes a note. Recall reads them back. And a note that says trust turns the question off for 1 draft, everywhere.
Point number 5. You added a tool on your own.
find_note took 5 lines and the same 5 steps. That was run number 4, and the list has still not changed by a word.
1. Write the plain Python function
2. Put the @mcp line above it
3. Write the one-line docstring
4. Restart Claude Desktop
5. Ask Claude to use it
Write the plain Python function. Put the @mcp line above it. Write the one line docstring. Restart Claude Desktop. Ask Claude to use it.
What module 4 brings
So what is coming next?
Module 4 pays a promise from lesson 1. The draft is finished in your Drive, and it still goes nowhere. You copy it into Substack by hand, which is exactly where you came in.
In module 4 Scribe learns a second service, Substack, in the same 5 steps. Then it comes off your laptop and onto a web address, with 1 line changed.
Grab the module 4 checkpoint before you start. It holds your full server as it stands today, with the guard and the memory working.
Where the map stands
So where does our map stand at the end of module 3?
13 boxes lit, and 3 still dark. Substack, the web address, and the registry. Module 4 lights all 3.
Bye now, and I will see you in the next lesson.
What we covered
- The asking belongs to the host until you own it. Claude Desktop asks before a tool runs, but 1 click on Always allow switches that off. A question that must always be asked has to live inside your server, because that travels to every app.
- The guard is 3 small jobs, not 1 big one: a fence that keeps Scribe in your folder, a wrapper that turns every Google refusal into a sentence, and a question on the argument so Scribe asks before it writes.
- A guard is only a guard once you have attacked it. Try a path, an empty find, a no, and Google. You get 4 refusals, 4 plain sentences and the draft untouched every time. Run break it dot pie after every change to the server.
- A chat is where the words live, and the words do not leave the chat. So the rules live in a file next to your server. Remember writes a note, Recall reads it back, and a note that says trust turns the question off for 1 draft, everywhere.
- You added a tool on your own. Find note took 5 lines and the same 5 steps. That was run number 4, and the list has not changed by a word.