Three real MCP breaches: “GitHub” , “CVE-2025-6514” , “Microsoft Research” - share the same root cause: no hard execution boundary. This blog breaks down why IAM and Docker fall short for agentic workloads, and how WebAssembly + WASI’s three core primitives (linear memory isolation, fuel counting, WASI pre-opens) solve the problem that your current security stack can’t.