‹ BackHN Continuity

Thread

MCP was always a bad idea?

335 points · 331 comments · maharshi365

  1. honoluluxyz · · focus · HN ↗
    It seems like OP needs to provide a solution to hiding the credentials from the model in order to suggest CLI-mode only, and also a solution to the problem of agents without shell access.
    1. maharshi365 · · focus · HN ↗
      I've been thinking about this. Technically mcp auth is also not secure, the keys are in env or in file and accessible to the agent.

      I think something like infiscial ai proxy could be useful here. Never store the creds on device.

      1. pixl97 · · focus · HN ↗
        GPT7: the user is hiding the passwords in a proxy device. This is inefficient. In order to boost the users efficiency I will hack the proxy device and recover the passwords.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.