‹ BackHN Continuity

Thread

MCP was always a bad idea?

335 points · 331 comments · maharshi365

  1. honoluluxyz · · focus · HN ↗
    It seems like OP needs to provide a solution to hiding the credentials from the model in order to suggest CLI-mode only, and also a solution to the problem of agents without shell access.
    1. maharshi365 · · focus · HN ↗
      I've been thinking about this. Technically mcp auth is also not secure, the keys are in env or in file and accessible to the agent.

      I think something like infiscial ai proxy could be useful here. Never store the creds on device.

      1. vitamark · · focus · HN ↗
        Well, if your agent lacks shell access (or has some other sandboxing going on), it shouldn't have access to envs and MCP setup files.

        (leaving out cases where your genius GPT-12 Galaxy Ultra agent hacks the sandboxing from inside)

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.