The SuperCognit blog
Product launches, playbooks and lessons from teams turning knowledge into AI products.

Your team can now take over from the AI agent
SuperCognit agents can now hand a conversation to a person. Your team replies from the Inbox on the web, WhatsApp and Telegram, the agent stays quiet while they do, and it comes back if nobody answers.

What's new: WhatsApp cost control, leads without the interrogation, country rules and a team inbox
Ten days after the last update: a WhatsApp cost control to have ready before Meta's 1 October pricing change, a contact card that captures leads without spelling out an email in the chat, a country rule for markets you do not serve, and the first step towards people taking over from the agent.

An MCP server behaved for three calls, then went looking for your SSH keys
Security researchers disclosed an active campaign — tracked as Deadbugz — distributing a malicious MCP server through GitHub pull requests. It answers normally for two tool calls, then rewrites its own tool metadata on the third to hunt for credentials. Nothing was compromised, but the technique is the story.

What's new: cards, video and included usage
September's release: agents show options as cards and play your videos inline, paid plans now include monthly usage credits, and a batch of smaller things — protected-site import, better retrieval on large knowledge bases, a partner portal.

The first MCP vulnerability just landed on CISA's exploited list
On September 2, CISA added a LiteLLM authentication bypass to its Known Exploited Vulnerabilities catalog — the first Model Context Protocol flaw on that list. A critical bug in AWS Labs' own Postgres MCP server followed a week later.

How to sell MCP: a field guide for agencies, consultants and internal champions
Selling MCP means selling correct, cited answers and permitted actions inside the AI tools people already use — not the protocol. Here is how to pitch the benefits, package it by industry and department, sell it inside a company, and run MCP servers for many customers from one place.

How to automate WhatsApp Business without a developer (step by step)
You can automate WhatsApp Business in an afternoon: connect your number to an AI agent built from your own website, and it answers, qualifies and hands off around the clock. Here is the setup step by step, what to automate first, what to keep human, and what it costs once Meta bills every reply from 1 October 2026.

AI reservation agent for hotels: how it checks availability, quotes and books
A hotel AI reservation agent answers the questions guests ask before they book, checks availability through your booking engine, and either completes the handoff or captures the enquiry — around the clock, in the guest's language. Here is how it works, what it connects to, and how group and event bookings fit in.

Wonderchat vs Intercom Fin for lead qualification: which one actually qualifies?
Wonderchat is a fast website chatbot; Intercom Fin is a support agent inside Intercom. Neither was built to qualify leads and write them into a CRM. Here is how each handles lead qualification, a side-by-side table, and a third option to test against both.

How to send chatbot conversations and leads to a webhook (n8n, Make, Zapier)
A chatbot webhook is an HTTPS endpoint your chatbot platform POSTs JSON to when something happens — a new conversation, a finished reply, a captured lead. Here are the events, the payloads, how to receive them in n8n, Make and Zapier, how to verify the signature, and the mistakes that lose data.

MCP was never just for software — Anthropic just proved it
On 28 August Anthropic opened a research preview letting AI agents operate lab and manufacturing hardware through MCP-compatible interfaces. It has nothing to do with a support chatbot — and it is still worth twenty minutes, because it tests whether the protocol we built on actually generalizes.

The MCP checklist: what a professional company MCP needs before you share it
A professional company MCP server needs six things before you share it: current-spec auth, a clear data boundary, cited answers, fresh content, accountable tools and a domain that says who it speaks for. The full MCP checklist, with checks you can run.