‹ BackHN Continuity

Thread

MCP was always a bad idea?

335 points · 331 comments · maharshi365

  1. simonw · · focus · HN ↗
    This article entirely misses the value that MCP brings today.

    Sure, there's almost no reason to use MCPs if you are running a full-blown terminal agent (Claude Code, Codex, Meta Muse, OpenClaw etc) with unfettered internet access - just let it call APIs directly.

    If you want to operate something that's less YOLO than that, you'll find yourself wanting:

    1. Control over exactly which external services it can access

    2. A way to handle authentication that doesn't allow the agent to directly access API keys

    3. A sensible UI to allow users to connect and authenticate further services

    4. Strong audit logging for what's going on

    MCP makes all of that so much easier to provide.

    Thinking MCP is obsolete because full coding agents don't need it misses out on all of the other things we might want to build.

    1. maharshi365 · · focus · HN ↗
      Were in a world where agents are more autonomous. Need stuff to be easier for agents and not humans
    2. rsolva · · focus · HN ↗
      Exactly, in our company, we have built MCPs that simplifies interactions with internal tools we use a lot, which saves time and tokens. Sure, we could let the agent poke and fumble around with a not-so-ideal API too, but it makes sense to formalize it and give the agents quick access to what we want it to fetch 99% of the time.
      1. 0x445442 · · focus · HN ↗
        What interactions with internal tools? If you can answer that question then the clankers can help you write a deterministic program for that same interaction and you only spend the tokens once.
        1. piva00 · · focus · HN ↗
          I've been doing this myself but it's been extremely hard to get buy-in from the rest of the org. They keep churning MCPs for deterministic interactions while I have tons of little tools written by clankers, not only for clanker-use but also for my own use when needed.

          Best of both worlds in my view.

        2. 0x696C6961 · · focus · HN ↗
          Yeah that's a good idea. Then we should standardize these tools and find an easy way for agents to discover and use them. ... Oh wait
          1. mjmas · · focus · HN ↗
            And call it not-closed API or something like that.
          2. 0x445442 · · focus · HN ↗
            Just tell the clanker to read the api documentation that should already exist. You dont need an MCP server for that.
          3. jimbokun · · focus · HN ↗
            Congrats you just invented the Unix shell!
            1. wezabis · · focus · HN ↗

              [dead]

        3. locknitpicker · · focus · HN ↗
          > If you can answer that question then the clankers can help you write a deterministic program for that same interaction and you only spend the tokens once.

          The MCP is the deterministic program.

          You need to take a step back and look at the problem you're discussing. What's exactly this MCP thing? It's a protocol to allow agents and coding assistants to access tools, services, and data sources, through a standardized interface.

          It's the interface for your deterministic program. That's it.

          1. 8note · · focus · HN ↗
            they were suggesting that you take the agent out of the run time tool usage
            1. locknitpicker · · focus · HN ↗
              > they were suggesting that you take the agent out of the run time tool usage

              That only applies if you are talking about a well established recurrent workflow. That's not how MCPs are used to begin with.

            2. themgt · · focus · HN ↗
              It's easier if you started a while back shunning all human labor (including your own) in favor of fully deterministic systems. Reality is deterministic so your company or project logically can be run off a single compiled binary with formal verification of correctness for every possible scenario.
              1. jimbokun · · focus · HN ↗
                Heisenberg begs to differ with your view of reality.
                1. shwaj · · focus · HN ↗
                  So does Gödel. Maybe it was a joke? Unclear.
          2. jimbokun · · focus · HN ↗
            A protocol is not a program.
        4. Sayrus · · focus · HN ↗
          Retrieving messages from Slack over MCP allows a shared read-only bot account accessible from the web browser and CLI. Setup is automated so users can just ask Claude to read them and do something.

          Sharing Slack with Claude:

          - Using the "normal" way, it shares too much, including privates messages.

          - Using your own token, it doesn't work with Claude.AI or Cowork and requires you to go to slack.com to generate an application, tokens and more.

          - Using a shared token, now you need context to tell Claude to retrieve it. It still doesn't work for non-Claude Code workflows. Rotation may break currently running workflows.

        5. lanstin · · focus · HN ↗
          Yeah. Like I had Claude code write an upload Slab script, and a few linear integration scripts, now it just runs these to interact with those systems. I had it write a redshift proxy that doesn’t take login creds and is just a logging read only account but it can just write sql to research to its hearts content (some columns hashed on replies) and I don’t need much trust but I get a lot of good analysis and verification done.
        6. jimbokun · · focus · HN ↗
          Yes, having LLMs write deterministic programs is still an under used solution.

          Less token spend, lower latency, more predictable results compared to having the LLM perform the task directly every time.

      2. deadbabe · · focus · HN ↗
        The simplified interactions are how it should have been designed in the first place.
        1. yorwba · · focus · HN ↗
          It's difficult to come up with the optimal workflow on the first try. So an API should typically start out flexible even at the expense of complexity, in order to enable experimentation, and then you can optimize to make the common case simple, once you know what the common case is.
          1. jimbokun · · focus · HN ↗
            Sure but that common case should go into the core APIs, not an MCP.
            1. dominotw · · focus · HN ↗
              agreed lots of ppl writing mcp as a lipstick on the pig.
              1. lazyasciiart · · focus · HN ↗
                Yea my company is willing to pour money into an MCP but has concretely resisted attempts to improve or care about the API for years.
              2. rsolva · · focus · HN ↗
                MCP is exactly the lipstick we needed to put on our pigs, APIs that is not ours, but open source tools we use internally and also wanted to expose to our agents.
                1. cindyllm · · focus · HN ↗

                  [dead]

    3. 0x696C6961 · · focus · HN ↗
      Even if your agent has internet access, why waste tokens having it re-discover and re-implement its own API client each time? It doesn't make any sense.
      1. marcelo-earth · · focus · HN ↗
        This is my favorite position, the advantage of an MCP tends to lie more in token optimization.
        1. deadbabe · · focus · HN ↗
          On the contrary, you burn more tokens with MCP.
          1. 0x696C6961 · · focus · HN ↗
            This is not true.
            1. cowmix · · focus · HN ↗
              I guess it depends on the implementations.

              When I use the Atlassian CLI vs their MCP server, I tend to see something like half the token burn with the CLI with more accurate results.

              That could be an Atlassian issue but that's the results I'm seeing.

              1. dnautics · · focus · HN ↗
                yeah MCP contains a provision for some blocktext for instructions. If your MCP has walls of text in those instructions, it will burn more tokens that a terse MCP.
            2. dnautics · · focus · HN ↗
              How do you think the LLM becomes aware of which mcps are available? Vibes?
              1. 0x696C6961 · · focus · HN ↗
                It depends on the harness. But most use a tool_search tool.
                1. dnautics · · focus · HN ↗
                  yes and using that tool does what with tokens?
                  1. [deleted] · · focus · HN ↗

                    [deleted]

                  2. 0x696C6961 · · focus · HN ↗
                    You seem confused.
                    1. dnautics · · focus · HN ↗
                      I'm not. You can build an MCP and throw a ton of junk in there and bloat the shit out of its token cost. So, really, "it depends".
        2. athrowaway3z · · focus · HN ↗
          In what way?

          Not sure whats the norm nowadays, but it used to be MCP descriptions were loaded in from the start.

          In any case, to be cheaper the `cli --help` command needs to more noisy than the json description.

          Finally, and the really big one: cli can be composed with `grep`, `jq` , etc.

      2. hypercube33 · · focus · HN ↗
        For me, I have a service that has multiple vectors of what would be called an API - PowerShell Modules, WMI, RESTFUL Web Services, some are available, some can do some things, some are more direct, some are not allowed with enterprise security etc.

        Either way, I don't do what you suggest. I have self-learning rules and have the models build a well-rounded API engine once, then re-use it with query scripts through skills. Its portable and flexible in many environments.

        1. 0x696C6961 · · focus · HN ↗
          No one is saying to wrap your local power shell modules in an MCP. That would be pointless and stupid.
      3. mexicocitinluez · · focus · HN ↗
        > re-implement its own API client each time

        Is using curl considered re-implementing your own api client each time?

        1. 0x696C6961 · · focus · HN ↗
          Making the model use curl is even stupider. It still needs to do the same amount of work to lookup and understand the API contracts (assuming those are even public). But now it also needs to juggle the auth flows and marshalling at the tool call level.
          1. mexicocitinluez · · focus · HN ↗
            You said ""re-implements an API client" which means you either don't know what curl is or don't know what an api client is. So I'd chill on calling things "stupider" when you don't have a strong grasp on the words you're using.
            1. sophacles · · focus · HN ↗
              What is "implementing".... I'd define it as "figuring out the workflow, and storing it in a way that allows reuse". This could be a program written in assembly, or rust, or even python. Or it could be a shell script that calls curl. Or it could just be a set of tokens in the current session. Outside of the computer it could even be a set of processes people do, or a mechanical device.

              If it's just a set of tokens in the current session, well then next session it has to figure out the workflow, and then store it in a way to use in the next session.

              Seems like maybe you should take your own advice.

              1. mexicocitinluez · · focus · HN ↗
                How does the definition of "implementing" change the fact that curl quite literally is an api client? It's an implemented api client.

                > Seems like maybe you should take your own advice.

                Seems like maybe if you have to use your own custom definition of a word in order to support a point you might not have one. lol.

                1. sophacles · · focus · HN ↗
                  Nonsense, curl is a tool for executing a single http request.

                  Many apis require several requests to get things done. (one to auth, one or more to fecth resource ids, one or more to modify resources, etc).

                  That would be a series of curl calls with logic applied to the output of each call to curl. An api client just does those things in a single function call. The steps are the same, but in one case the AI has to figure out each curl call and implement the logic, rather than just call the function.

                  1. mexicocitinluez · · focus · HN ↗
                    lol Id say the nonsense is tying multiple calls to the definition of an api client.

                    Irony died in this comment thread.

                    1. sophacles · · focus · HN ↗
                      By your logic 'ls' is a file manager, 'grep' is a search engine, and 'echo $X >> /proc/sys/$Y' is a settings manager.

                      It makes sense though. It's the same logic that allows you to say promting an AI with "do a simple thing for me" makes you a programmer, and prompting an AI with "what is an api" allows makes you knowledgable about computers.

            2. 0x696C6961 · · focus · HN ↗
              In your mind, is netcat also an API client? When normal people talk about api clients, they're referring to an sdk or a cli which provides a simpler interface for a specific API.
              1. mexicocitinluez · · focus · HN ↗
                You're not implying netcat and curl are synonymous are you?

                And When "normal" people talk about api clients? lol This site is wild.

                1. 0x696C6961 · · focus · HN ↗
                  Alright dude ... Either you have major comprehension issues or you're arguing in bad faith. But I'm done responding to you.
      4. jimbokun · · focus · HN ↗
        Did you know that computer programs, once written, can be stored to disk once and run many times?
        1. estetlinus · · focus · HN ↗
          I love the level of sassiness this debate brings forward in people
        2. 0x696C6961 · · focus · HN ↗
          People like you can't seem to comprehend that there are use-cases other than your little local claude code workflow.
        3. nitwit005 · · focus · HN ↗
          Sure, but if you have a staff of 10000, you're doing this 10000 times. Unless you share that in a common place, and now you're re-inventing the thing we're claiming not to need.
    4. barrkel · · focus · HN ↗
      A CLI doing all this is still a better UI for the agent though.
      1. 0x696C6961 · · focus · HN ↗
        What does that even mean?
        1. bdangubic · · focus · HN ↗
          totally makes no sense. so weird after all this time people don’t “get” the value of MCPs, so weird
      2. viccis · · focus · HN ↗
        What if the agent doesn't have a CLI?
        1. barrkel · · focus · HN ↗
          You hobble the expressiveness of the LLM and reduce its capability.

          Think of an agentic harness as like a kind of body for the LLM. It gives it primitive inputs (read_file, web_search or whatever) and primitive outputs (edit file, respond to user, etc). Give it a command line environment (in a locked down sandbox, with as few or as many tools as you prefer), and you've given it a toolbox. It can do a whole lot more, faster and more efficiently. It can compose tools together. It makes fewer transcription errors manually shifting data around. It can tame verbosity with good protections in the harness and access to grep, sed and awk.

          It's really up to you how useful you want your agent to be.

          1. viccis · · focus · HN ↗
            Yeah but you're still assuming it's running on someone's machine with a CLI to even use.
            1. barrkel · · focus · HN ↗
              Someone can be OpenAI/Anthropic/whomever.

              If you don't have something running somewhere, you don't have an agent, you don't have a harness. You've got a token generator, an LLM from the 2024 era.

              1. viccis · · focus · HN ↗
                That's where you are completely wrong. The point of MCP is that you can have an agent and a harness without running raw CLI or Python commands. Very common for relatively lightweight loads that involve shuffling data around between APIs, often run in a tiny serverless task.
                1. barrkel · · focus · HN ↗
                  Sure, you have an LLM which can invoke functions. I will say that without storage and composition, you're asking for hallucination. LLMs are not deterministic and while they're good at regurgitating text - you can see how replies in an instruct model are structurally keyed off the question - they will rephrase, adjust, "correct" data they're schlepping from one call result to another call input. And one noisy MCP call and there goes your context.

                  You could build something with storage and composition out of MCP functions, but come on, have you seen how LLMs - particularly budget LLMs - try and invoke functions reliably? The amount of retries you have to hide, feedback you need to send back to the LLM about what it did wrong. Parameters get replaced with synonyms, arrays are passed for singular arguments and vice versa, structured inputs are flattened, etc.

                  So maybe you fine tune on interactions with your subset of MCPs, to improve reliability. But all you end up doing is reinventing a Unix-like command line, poorly.

                  Firecracker micro-VMs, gVisor, wasm sandboxes. There are ways to make this work that aren't heavyweight. Giving LLMs tools that they've seen how to use millions of times in training corpora just works better.

      3. pixlmint · · focus · HN ↗
        What if I don't want my agent to have terminal access though? I get the feeling many people here simply never worked with smaller models, those will confuse cli args really quickly once context expands, and then you have no idea what damage they might do. With MCP's, they get just the access they actually need. Is the Principle of least privilege just not something we want to apply anymore?
        1. barrkel · · focus · HN ↗
          CLIs, run in a sandbox as tight as your preferred choosing, live in an ecosystem, where, via pipes and redirection, input and output can be easily manipulated. An agent can do similar things but more laboriously (and less token efficiently) via Python or similar but it would still live in a sandbox somewhere.

          Going without the sandbox means hobbling the LLM. It can do things directly but is less able to construct ad-hoc programs to deal with looping, conditionality, tame verbosity, connect tools together, and so on.

          It's a choice to not give the LLM an environment. As you say, it can be necessary if you're using dumb models. I don't find it particularly worth the trade most of the time.

          1. pixlmint · · focus · HN ↗
            If not even OpenAI can properly box in their models I definitely won't trust myself to do so with the very limited time available to me, and instead just use a standard that's already defined, and proven to work.
            1. barrkel · · focus · HN ↗
              By OpenAI, I presume you mean Irregular - these guys <a href="https:&#x2F;&#x2F;www.irregular.com&#x2F;about" rel="nofollow">https:&#x2F;&#x2F;www.irregular.com&#x2F;about ?

              These guys are the common factor, the guys running the evals that let all the AI agents out, it looks like.

    5. maharshi365 · · focus · HN ↗
      1. Control can be done via CLIs --&gt; api key based access controls. We have been doing it forever. 2. I think this really only applies to Oauth based MCPs. Many server support api key based auth, stored as files --&gt; security is still flawed imo. 3. This can be done via apis&#x2F;clis too --&gt; not something unique to MCP iimo 4. Same thing, not unique to MCP --&gt; api servers can also be logged

      MCP doesn&#x27;t inherently make this easier. its still requires engineering maintaincence.

      1. nortirn · · focus · HN ↗
        Having a standard does make sense though, because it lets agent services handle external calls in a standard way. So, for example something like Anthropic&#x27;s agent platform will proxy all MCP calls and hide the credentials so that you don&#x27;t have to worry about the agent leaking secrets into code&#x2F;logs&#x2F;the internet. Of course you could build a similar layer to proxy traffic to various APIs, but it becomes easier to make the whole thing plug and play if everyone agrees on the shape of the API (MCP).
        1. maharshi365 · · focus · HN ↗
          i think standards are good for low level things. APIs change, model behvaiors change, we basically are allowing an external service provider to control our agent prompts.
    6. mikeocool · · focus · HN ↗
      All of these things are perfectly possible with a plain REST API with an Open API spec and using some standard auth options, and an AI client that implements a reasonable “make api request tool” (just like the AI clients implement MCP today).

      I think the real value of MCP is that it allowed companies to say “we’re doing AI!” When they built an MCP server. Just saying “use our api” was a lot less exciting.

      Giving it a different name probably also helped cut through politics at companies where non-technical people didn’t want to open up user data with an API, but they did want to do AI.

      1. simonw · · focus · HN ↗
        Hah, I made that same point last December: <a href="https:&#x2F;&#x2F;simonwillison.net&#x2F;2025&#x2F;Dec&#x2F;31&#x2F;the-year-in-llms&#x2F;#the-only-year-of-mcp" rel="nofollow">https:&#x2F;&#x2F;simonwillison.net&#x2F;2025&#x2F;Dec&#x2F;31&#x2F;the-year-in-llms&#x2F;#the-...

        &gt; For a while it also felt like MCP was a convenient answer for companies that were under pressure to have “an AI strategy” but didn’t really know how to do that.

        I&#x27;ve since come back to MCPs, because I want to build my own agents without first having to solve the problem of effectively sandboxing Bash.

        1. mikeocool · · focus · HN ↗
          Yeah, from a design perspective MCP upsets me, because it’s a poorly designed standard and creating a good one could have been much easier.

          But you’re right, since clients don’t have a nicely sandboxed “make api request” tool, it’s basically the way to go for a lot of use cases.

          1. rsalus · · focus · HN ↗
            I think the new 07-28 spec is quite decent
        2. agentdev001 · · focus · HN ↗
          &quot;without first having to solve the problem of effectively sandboxing Bash&quot;

          Hopefully this is easier as time goes on. Of course- also policy on the egress

        3. otabdeveloper4 · · focus · HN ↗
          &gt; without first having to solve the problem of effectively sandboxing Bash

          &quot;Sandboxing bash&quot; is a problem that has been solved a zillion years ago already. Take your pick of any of the dozens of battle-proven solutions.

          1. simonw · · focus · HN ↗
            Which solution do you recommend?

            Bonus points if it&#x27;s available on both macOS and Linux and doesn&#x27;t come from a random unmaintained GitHub repository with a note in the README that says &quot;don&#x27;t run this in production&quot;.

          2. Sohcahtoa82 · · focus · HN ↗
            &quot;Battle-proven&quot; until an LLM decides it really needs to escape the sandbox you put it in and eventually succeeds.

            For personal work, I run Codex in a VM that contains only what&#x27;s necessary to do software development. Could it escape the VM? Sure, if there&#x27;s a zero-day in VMWare Workstation.

            Yeah, I&#x27;m using a pile driver when I really probably just need a hammer, but I&#x27;ve seen too many horror stories, and I don&#x27;t trust guard rails. Even if there was an option to limit Bash calls to read-only operations, I would be 0% surprised to eventually run into &quot;You&#x27;re absolutely right! `rm -rf &#x2F; --no-preserve-root` was a write operation! That&#x27;s totally on me.&quot;

        4. indymike · · focus · HN ↗
          MCP is one of those things that is &quot;too good enough&quot;.
        5. jimbokun · · focus · HN ↗
          Understood but it seems like effectively sandboxing cash is a very very important problem for the industry to solve!

          Would be a much more robust and general solution of the problem of controlling and auditing agentic access to sensitive information.

          1. tadfisher · · focus · HN ↗
            It&#x27;s such an important problem that it is sucking all available VC money into an exponentially-growing number of startups promising to make sandboxed agents safe and usable. In other news, MCP exists.
            1. jimbokun · · focus · HN ↗
              Honest question: which startups are trying to write a sandboxed-by-default easy to configure bash meant to be safely used by agents?
              1. tadfisher · · focus · HN ↗
                It&#x27;s not &quot;bash&quot;, it&#x27;s containers&#x2F;VMs&#x2F;whatever that are isolated from the host and run the agent, which can access a shell to do work.
        6. JambalayaJimbo · · focus · HN ↗
          What do you mean by sandboxing bash? Isn’t this about just having a tool like curl or Postman?

          Implanting an MCP client in your agent code isn’t all that different from calling requests or whatever

          1. simonw · · focus · HN ↗
            I mean the ability to have an agent run commands in a Bash shell without allowing them access to any file or environment variable visible to the user on that computer, and without allowing them uncontrolled internet access.
            1. JambalayaJimbo · · focus · HN ↗
              Program specific permissions (separate from the user operating them) are part of the Linux permissioning system already right? That doesn’t seem like an issue to me.

              I guess the main problem would be finding an API client that can easily plug into your harness, with a nice UI for turning specific APIs on and off.

      2. rgbrgb · · focus · HN ↗
        it&#x27;s mostly true but the mcp also installs the knowledge of that REST API in a standard way so that a user can ask &quot;what&#x27;s projected revenue this month?&quot; and it&#x27;ll know how to hit your company brain and answer
        1. jimbokun · · focus · HN ↗
          Or just write good API docs that humans can use too.
          1. rgbrgb · · focus · HN ↗
            most users i&#x27;m dealing with are not doc-reading developers. even getting them to tell claude to use tool X is pretty hit or miss whereas claude already knowing what tool to use is 100% hit with correct mcp tool descriptions.
      3. what-the-grump · · focus · HN ↗
        Pretty much, MCP is still a bad idea.

        LLMs perform significantly better and faster when you strap them to plain old apis&#x2F;and an open api spec with a search tool.

        My current MCP design is… grab a fastapi spec shove it into fastmcp, shallow wrapper, search tool for the full schema.

        Oh boy so exciting I just wrapped an api spec for no reason and have to host infra for the translation layer. If only we invented api gateways.

        But I am Mr. AI now.

        1. isbvhodnvemrwvn · · focus · HN ↗
          How do you handle credentials safely?
          1. SgtBastard · · focus · HN ↗
            Just leak them to the inference providers, obviously &#x2F;s

            If you have self hosted models and&#x2F;or self hosted APIs, maybe you don’t need MCP to provide a gateway to a secure resource.

            If neither of those things are true, you need an authenticating gateway&#x2F;proxy or a target API that supports single use credentials (and get the model to generate a call to use them).

            We can argue whether MCP is a good authenticating middle layer, but not whether one is required.

            1. jimbokun · · focus · HN ↗
              What about just handing the agent a token with limited time to live and constrained access permissions?
          2. what-the-grump · · focus · HN ↗
            You mean oauth? API keys?

            API gateway is a thing…

      4. blitzar · · focus · HN ↗
        &gt; For a while it also felt like MCP was a convenient answer for companies that were under pressure to have “an AI strategy” but didn’t really know how to do that.

        MCP was a convenient answer for companies that had spent the last few years shutting down APIs because allowing API access bad.

    7. prescriptivist · · focus · HN ↗
      Couldn&#x27;t agree more. MCP is just Tool Use and the terminal agents all have embedded tool uses like WebSearch, Bash, Grep, etc and those are just MCP by another name. CLI&#x27;s called by a model are just Bash Tool usage calls. Bash tool is just the most open ended broad MCP you can expose and what you gain is less context bloat (no specialized tool descriptions, just Bash) and what you lose is control over the agent -- until you setup a rigorous set of governing permissions on the Bash Tool.

      I have a fleet of sandboxed Claude Code instances running and they share files with each other. The files are stored on AWS but they don&#x27;t have access to AWS at all -- they can&#x27;t see the access keys. In fact they don&#x27;t know the files are on AWS. Instead they have a set of MCP tools for listing&#x2F;uploading&#x2F;downloading from an internal, virtual filesystem with a special URI handler (ie agentfiles:&#x2F;&#x2F;somefile.json) and the outer orchestrator of the Claude Code instances takes the MCP requests and does the actual file manipulation on Claude&#x27;s behalf. The LLM seems to adapt quite well to this strange, arbitrary filesystem and I get to keep these agents fully compartmentalized. And I have tool request logs and logs in the outer orchestrator for full auditing of the agents. MCP is a really natural fit for this kind of stuff.

      1. zahlman · · focus · HN ↗
        &gt; what you gain is less context bloat (no specialized tool descriptions, just Bash)

        Couldn&#x27;t they train the understanding of a specific tool set directly into the model instead of needing it to be in context? Like isn&#x27;t that basically what happens now with the Bash tool?

        Is there a reason we need to rely on such a high level of access for something that should really only ever be cleaning up the project directory, hitting the &#x27;Run Test&#x27; button and authoring some Git commits?

        1. blitzar · · focus · HN ↗
          Perhaps a little out of date now, but I found claude was better (trained?) with the gh command line than with the github mcp. For a $corp internal tool ... I don&#x27;t really see how and LLM would be able to be trained on it.
      2. kaoD · · focus · HN ↗
        &gt; MCP is just Tool Use

        I wish. <a href="https:&#x2F;&#x2F;modelcontextprotocol.io&#x2F;specification&#x2F;2026-07-28" rel="nofollow">https:&#x2F;&#x2F;modelcontextprotocol.io&#x2F;specification&#x2F;2026-07-28

        1. simonw · · focus · HN ↗
          The spec describes Resources, Prompts, Tools, and Elicitation.

          In practice, I believe Tools represent 95%+ of what people actually use MCP for. I&#x27;ve not seen an MCP with Resources or Prompts that seems to have widespread use of those features, and I don&#x27;t think I&#x27;ve ever seen anything implement Elicitation.

    8. viccis · · focus · HN ↗
      Exactly. A lot of people complaining about MCP are doing so because their only interactions with LLMs are via big batteries including code harnesses and don&#x27;t understand what kind of (usually much more domain-specific) agentic systems are being built. For example, &quot;CLI vs MCP&quot; doesn&#x27;t make any sense whatsoever if the agent doesn&#x27;t have access to a CLI!

      MCP suffers from its harebrained choice early on to load everything into context up front.

      1. williamse · · focus · HN ↗

        [dead]

      2. dnautics · · focus · HN ↗
        The other problem with MCPs is that the harnesses don&#x27;t auto-reconnect if you&#x27;ve enabled access. Connection status should be persistent
    9. locknitpicker · · focus · HN ↗
      &gt; Sure, there&#x27;s almost no reason to use MCPs if you are running a full-blown terminal agent (Claude Code, Codex, Meta Muse, OpenClaw etc) with unfettered internet access - just let it call APIs directly.

      I don&#x27;t think this is a valid statement too. I&#x27;ll explain why.

      A MCP server represents those APIs that agents and coding assistants can call.

      If you feel a need to provide data and services to agents through an API and feel so strongly about it and so compelled to implement your own APIs with the express purpose of being consumed by your agents, wouldn&#x27;t it make sense to develop an API that is designed purposely for agents using a protocol designed to meet their needs and simplify their work?

      Because that&#x27;s what MCP is all about.

      Nowadays, with the improvements in tool-calling and the dissemination of agent skills, MCP&#x27;s value proposition isn&#x27;t as clear as back when those weren&#x27;t a given. But once you face usecases to either centralize your tools across an organization, manage access, and be able to audit it&#x27;s usage, right now there is no alternative to MCP.

      1. jimbokun · · focus · HN ↗
        Agents are perfectly capable of using the same APIs designed for humans.
    10. jrm4 · · focus · HN ↗
      Real hard to not think-

      &quot;This is a job for a CLI&#x2F;terminal, which is absolutely a million times easier to learn today, thanks to AI.&quot;

      Feels like MCP is still a product of -- well, &quot;AI as a product&quot; brain, which I have no love or use for. Give EVERYONE ALL the tools.

      1. crooked-v · · focus · HN ↗
        So how do you make that CLI tool work in the context of a web client?
    11. seanhunter · · focus · HN ↗
      Exactly. There are so many replies here of the form “MCP sucks. If you just do &lt;all the things mcp does a different way&gt; you don’t need mcp at all.”

      Well yes.

      1. mikeocool · · focus · HN ↗
        I think the point of those comments is this could have been much simpler for everyone if the model providers had given us some tools around existing standards.

        Instead they invented something new&#x2F;weird&#x2F;complex standard, and then every client implemented slightly differently (and different parts of it).

      2. lelanthran · · focus · HN ↗
        &gt; Exactly. There are so many replies here of the form “MCP sucks. If you just do &lt;all the things mcp does a different way&gt; you don’t need mcp at all.”

        See my previous reply to simonw elsethread.

        It&#x27;s not &quot;If you just do &lt;all the things mcp does a different way&gt; you don’t need mcp at all&quot;, it&#x27;s that many of us were already doing that in a CLI prior to LLMs. You think only github and amazon had CLI clients?

    12. jwr · · focus · HN ↗
      &gt; there&#x27;s almost no reason to use MCPs if you are running a full-blown terminal agent

      I disagree. Adding &quot;<a href="https:&#x2F;&#x2F;mcp.linear.app&#x2F;mcp" rel="nofollow">https:&#x2F;&#x2F;mcp.linear.app&#x2F;mcp&quot; and having everything happen (discovery, usage, updates to the API, etc) without having to install or configure anything else locally is a big deal.

      1. shibel · · focus · HN ↗
        Funny you mention Linear’s specifically, I just posted about moving to a CLI instead because of the MCP’s egregious token-usage [1]. While this doesn’t discount the points you mentioned, I think the context savings (which can be huge, I hadn’t listed all differences in that post) outweigh them specifically in Linear’s case. It is just too inefficient in that regard.

        Edit: this of course says nothing about MCP vs API&#x2F;CLI in general. It’s just a bad implementation by Linear.

        1: <a href="https:&#x2F;&#x2F;thebiglog.com&#x2F;links&#x2F;linear-cli-instead-of-linear-mcp" rel="nofollow">https:&#x2F;&#x2F;thebiglog.com&#x2F;links&#x2F;linear-cli-instead-of-linear-mcp

        1. w0m · · focus · HN ↗
          This surprises me a bit. I&#x27;ve found much better token usage with a proper&#x2F;efficient MCP as even with a deep &#x2F;skill defining usage, parsing MCP results is generally just better&#x2F;more efficient than parsing CLI results. I say this having written a CLI tool explicitly for harness usage, and leveraging MCPs for the same.

          I&#x27;m sure there are bad MCPs and great CLI tools that parse poorly&#x2F;well via harness, but I&#x27;d be curious on an better research study.

          1. shibel · · focus · HN ↗
            Your comment doesn’t contradict mine and mine doesn’t contradict yours. Linear’s MCP is just (very?) inefficient. I explain the source of the difference in the last two paragraphs.
          2. estetlinus · · focus · HN ↗
            How much are using Linear if token usage is a problem? Sounds like a case of straining at a gnat and swallowing a camel.
    13. baalimago · · focus · HN ↗
      In essence: MPC servers are the sandbox
      1. jimbokun · · focus · HN ↗
        True but a pretty shitty sandbox and we need a less leaky and more general sandbox solution ASAP.
        1. baalimago · · focus · HN ↗
          &gt;pretty shitty sandbox

          Well, speak for yourself. My MCP servers are pretty solid.

          There&#x27;s nothing in the protocol making them inherently poor other than perhaps popularity, causing a swarm of people vibe-coding things they don&#x27;t understand.

        2. everforward · · focus · HN ↗
          I&#x27;ve taken to sandboxing my entire agent in a Docker container. I wrote a tool that pretends to be an ACP client but is actually making Docker containers, copying files I specified in, bind-mounting, etc, and then proxying ACP via websocket to an agent in the container (except the ACP terminal&#x2F;FS commands, those happen in the container).

          It works well, though there is some leakiness around paths. I opted to make it place&#x2F;mount files at the same path as on the host so paths are the same (as opposed to manipulating the ACP messages to modify paths on the fly, that felt messy and buggy).

          Configurable networking is on my list for the future, but I haven&#x27;t decided whether to start with IP-level firewalls or if it&#x27;s better to start with a proxy and firewall rules to force traffic to it. IP firewalls suck for APIs that might have semi-dynamic IPs.

          [1] <a href="https:&#x2F;&#x2F;github.com&#x2F;SethCurry&#x2F;abyss" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;SethCurry&#x2F;abyss

    14. socketcluster · · focus · HN ↗
      MCP definitely has its niche in certain environments. It&#x27;s good for a specific kind of constrained problem; not so constrained that you could solve the problem with just Node.js + fetch call to LLM API but not so open that you&#x27;d want to let the AI agent directly invoke any service it wants over the web. The latter is what happens if you give the agent access to curl.

      Though I agree with OP&#x27;s point of view that MCP was overhyped for too many use cases. Complex agent-system integration problems are usually better solved with just AI agent + curl + SKILL.md. It&#x27;s just way more flexible.

      It&#x27;s another variant of the &#x27;fat client&#x2F;thin server vs thin client&#x2F;fat server&#x27; debate. Some people want rigid, thin (e.g. web-based) frontends with the LLM doing work in secret behind the scenes. Others want fat, versatile frontends through which the LLM can interact with the user&#x27;s own environment.

      I&#x27;ve always been a fat client guy and this time is no exception. I doubt the constrained approach is going to lead ground-breaking innovation. I also wish companies would treat SKILL.md + curl as the main mechanism for agent tool calling as opposed to MCP. MCP is niche.

      1. anon84873628 · · focus · HN ↗
        That niche environment is all SaaS-to-SaaS integrations. The client doesn&#x27;t want to have users struggling to get every integration working on their platform. The service providers don&#x27;t want to have to support non-standarized behavior by every client.
      2. richsong · · focus · HN ↗

        [dead]

    15. lelanthran · · focus · HN ↗
      &gt; This article entirely misses the value that MCP brings today.

      Well, me too. I see the only advantage over a CLI app being an agreed-upon convention for syntax (not semantics).

      I have a CLI interface to my webapp, not an MCP.

      &gt; If you want to operate something that&#x27;s less YOLO than that, you&#x27;ll find yourself wanting:

      &gt; 1. Control over exactly which external services it can access

      Access control is not built into my CLI, it&#x27;s built into the WebApp.

      &gt; 2. A way to handle authentication that doesn&#x27;t allow the agent to directly access API keys

      My CLI takes credentials from the environment, which it uses to talk to endpoints. The caller sets the environment, then calls the CLI program. The caller provides no way for anyone sending it input (the Model) to request or retrieve environment variables.

      &gt; 3. A sensible UI to allow users to connect and authenticate further services

      The parts of my WebApp that relays or re-requests to other third-party services handles access control.

      &gt; 4. Strong audit logging for what&#x27;s going on

      Not sure what this is supposed to mean: the WebApp already has auditing logs.

      &gt; MCP makes all of that so much easier to provide.

      Sure; I&#x27;m considering writing a purely deterministic shim for MCP around my CLI. The semantic&#x2F;information is the same, the only difference is syntactical in nature.

      &gt; Thinking MCP is obsolete because full coding agents don&#x27;t need it misses out on all of the other things we might want to build.

      It may as well be; coding agents are at one end of the control spectrum - run in bash, do anything&#x2F;everything (so they can leak credentials to the model, or the harness). But a CLI app doesn&#x27;t have to allow bash. My &quot;harness&quot; (using the term very loosely) can securely call other programs without giving its own caller a RCE via bash.

      1. simonw · · focus · HN ↗
        So you&#x27;ve built your own agent harness that allows the model to call only your CLI but doesn&#x27;t allow the model to run &quot;env&quot; and view the environment variables itself?

        Sounds to me like MCP with a slightly different interface.

        1. lelanthran · · focus · HN ↗
          &gt; So you&#x27;ve built your own agent harness that allows the model to call only your CLI but doesn&#x27;t allow the model to run &quot;env&quot; and view the environment variables itself?

          Yes, with the difference being it can call other CLIs, just not arbitrary CLIs.

          &gt; Sounds to me like MCP with a slightly different interface.

          It is, except that it is not limited to being called from harnesses. Also usable from bash (automated scripts), or even humans if hey want to run it on the command-line.

          TBH, my webapp(s) had this prior to 2020, because it made automation simpler so I could write shell scripts to do various things on the WebApp.

          1. simonw · · focus · HN ↗
            I did end up building my own CLI for calling MCPs, mainly to better understand the protocol but also to make them easier for me to interactively debug: <a href="https:&#x2F;&#x2F;github.com&#x2F;simonw&#x2F;mcp-explorer" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;simonw&#x2F;mcp-explorer
    16. podocarp · · focus · HN ↗
      Still don&#x27;t get what&#x27;s the advantage over just adding a special API key or a wrapper cli or whatever mechanism that achieves all of that without being a &quot;protocol&quot; and with all the context bloat. Like the github cli is a good example. You give it proper auth keys etc. and for sure there&#x27;s some telemetry in there about usage as well. If there isn&#x27;t then it&#x27;s easy to do from the api side too.

      Even if you don&#x27;t own the code or infra, like say a frontend team who wants models to test out the backend apis and do something. Well in that case how do regular devs do it? Do they also get unfettered access in the past? Surely there&#x27;s still some mechanism you can repurpose for agents to use?

      I&#x27;m not trying to argue I&#x27;m just saying I didn&#x27;t catch on the first time mcp was a thing and I still don&#x27;t know what it&#x27;s doing now.

      1. simonw · · focus · HN ↗
        If a full coding agent can access a CLI tool. that agent can almost certainly access the API keys being used by that tool. They can go as far as decompiling binaries, or rewriting them to log the key before it is used.

        If you are worried about a prompt injected agent stealing your keys, that&#x27;s a problem.

        (There is a way around that: you can use an HTTP proxy that inserts those credentials but otherwise lives outside of the agent&#x27;s realm of influence. MCP is a whole lot easier though.)

        1. lelanthran · · focus · HN ↗
          &gt; If a full coding agent can access a CLI tool. that agent can almost certainly access the API keys being used by that tool.

          So, don&#x27;t do that then?

          Why do you need to use a full coding agent as the interface between the model and the CLI tool?

          A 10-line program can do the wrapping of any existing CLI program so that environment is not leaked to the model, while providing the CLI program with the environment as well as restricting what programs can be called to a whitelist.

          If you CLI program is echoing its keys in the response, or the endpoint is echoing keys back, that&#x27;s not a problem that can be solved with MCP anyway.

          1. simonw · · focus · HN ↗
            So you&#x27;re building a custom harness here that provides tools, and you&#x27;re wiring up your custom harness to effectively do a subprocess execution of a CLI script for every tool call the model request?

            One reason to switch to MCP here would be to avoid the overhead of forking a new process for every tool call, and to enable maintaining state between tool calls.

            (That performance overhead is so trivial as to not be worth caring about, but the state thing may be useful - keeping a stateful browser session running between tool calls is harder with a CLI, for example.)

            1. lelanthran · · focus · HN ↗
              &gt; So you&#x27;re building a custom harness here that provides tools, and you&#x27;re wiring up your custom harness to effectively do a subprocess execution of a CLI script for every tool call the model request?

              Well, yeah. Subprocess execution is on the order of double-digit milliseconds. The &quot;wiring up&quot; is maintaining a whitelist of what tool commands map to which executable. It&#x27;s a lookup table with very little maintenance required.

              &gt; One reason to switch to MCP here would be to avoid the overhead of forking a new process for every tool call, and to enable maintaining state between tool calls.

              I feel like I am taking crazy pills :-&#x2F;

              The overhead of forking, on the ancient machine I call my desktop, is at most double-digit milliseconds. The state isn&#x27;t being tracked by the MCP server anyway, it&#x27;ll be tracked by the harness and&#x2F;or the model, no?

              My main reason for adding MCP support is so that existing callers that want to use my WebApp(s) can just use it without needing any changes on their side.

              IOW, I am going to add it at some point, but not for the reasons you give. I&#x27;ll add it to be compatible.

              1. simonw · · focus · HN ↗
                You didn&#x27;t address my comment about state. If you&#x27;re driving something like Playwright you need a way to maintain state between tool calls.

                (Oddly enough I did solve that with my own CLI tool for running browsers during my &quot;who needs MCP&quot; phase, but it&#x27;s a bit of a nasty hack that involves leaving files with PIDs lying around: <a href="https:&#x2F;&#x2F;github.com&#x2F;simonw&#x2F;rodney#directory-scoped-sessions" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;simonw&#x2F;rodney#directory-scoped-sessions and <a href="https:&#x2F;&#x2F;github.com&#x2F;simonw&#x2F;rodney&#x2F;blob&#x2F;a842432246f39775ccb14f0de72565b2c216b5b6&#x2F;main.go#L81" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;simonw&#x2F;rodney&#x2F;blob&#x2F;a842432246f39775ccb14f...)

                1. silbercue · · focus · HN ↗

                  [dead]

        2. jimbokun · · focus · HN ↗
          Why not just give the agent a short lived token with limited access rights?

          We have reached the point where we need to control agent access the same way we control human access to systems.

    17. pragma_x · · focus · HN ↗
      As someone who has never used MCP, or allowed an AI to directly talk to APIs, putting something between a model and a service just seems like common sense. If nothing else, it presents an opportunity to tightly control what the AI is allowed to do with external services, especially if the MCP code is outside of the AI&#x27;s context. I would go as far as to say it&#x27;s a necessary security measure.
      1. dominotw · · focus · HN ↗
        well if you realease an api you should make sure its usable for ai out of box without &#x27;something in between&#x27;. You should always assume ai might be directly calling your api.
        1. anamexis · · focus · HN ↗
          And if you don&#x27;t have a public API, you should always assume AI will be using your UI, reverse engineering your private API, and driving it directly.
          1. cruffle_duffle · · focus · HN ↗
            I absolutely love when they do that unprompted. I once asked a Claude work agent to go pull comparable apartment listings and somehow it’s subagent reverse engineered like rentcafe or whatever’s private API to get the data. All unprompted.

            So yes. Absolutely assume AI agents acting on behalf of their humans are finding all the token efficient ways to get at your sites data.

        2. Tractor8626 · · focus · HN ↗
          Ai can&#x27;t use any api out of box. It requires thing called &quot;harness&quot; to use anything.
      2. jimbokun · · focus · HN ↗
        The service itself needs to control what the agent can access.

        Relying on an intermediary to provide access controls, and that agents will never access the service directly, seems dangerous and naive.

        1. jayd16 · · focus · HN ↗
          What? Why? More is more but you&#x27;re arguing a security proxy is a dangerous and naive pattern?
          1. jimbokun · · focus · HN ↗
            What’s the advantage of MCP over a regular old security proxy?
            1. Sattyamjjain · · focus · HN ↗

              [dead]

        2. anon84873628 · · focus · HN ↗
          And it&#x27;s easy for the service to do that by hosting a remote MCP server.
        3. Tractor8626 · · focus · HN ↗
          Agent doesn&#x27;t have api key to access service directly
      3. ActorNightly · · focus · HN ↗
        The better solution for security is sandbox execution. Most agents used in practice, if given terminal access, can find ways to get around most of the MCP restrictions.
    18. adverbly · · focus · HN ↗
      &gt; MCP makes all of that so much easier to provide.

      Easier being the key!

      Right now it really does feel like early web days where like 5% of the population is adopting things, but most people just get confused and don&#x27;t participate.

      This is why I&#x27;m pretty excited about WebMCP in particular!

      WebMCP aligns more stakeholders than pure MCP - which seems heavily biased towards model providers. It also seems like it has the potential for a much cleaner ux.

    19. jimbokun · · focus · HN ↗
      I feel like this would build a false sense of security.

      Authentication and access controls must be able to withstand an agent with full shell access. And auditing must be on the server side to provide a full picture of all activity from all clients, whether human or agent.

      We must treat agents as clever humans and secure and audit data access accordingly. The era of thinking we can handle agent access to sensitive information differently from human access has passed.

      1. simonw · · focus · HN ↗
        My point about MCPs here is that they provide a way to make those secrets and API keys deterministically inaccessible to the agents - even agents that&#x27;s have a shell execution environment.

        That&#x27;s the opposite of a false sense of security.

        1. mjburgess · · focus · HN ↗
          just use an api gateway (ie., a reverse proxy for apis), eg., envoy. This should also be connected to observability and finops style management anyway rather than leaving it to model providers.
        2. woodpanel · · focus · HN ↗
          I noticed the security aspect to be one of the main selling points in corporations for going MCP (and one aspect that is underrepresented here).

          However, maybe I&#x27;m missing something but how is defining access rights in an application layer the agent has access to more secure than defining the access rights at the target application itself?

          Sure, hiding the filesystem via encapsulation tricks is one way to go. But what is the real-world usage-style of this vs. all MCP usages? I&#x27;d wager 1-10% are spending this extra effort, while 90% of users basically run shims so that they can expose APIs to their LLMs, for which they have no&#x2F;bad access rights management.

      2. brabel · · focus · HN ↗
        Without tools LLMs can do nothing more than emit text. You are probably assuming a harness is provided to the LLM with shell access but that is absolutely not necessary for LLM usage depending on the use case. For interesting stuff, you do want to provide some tools, but nothing with the power of a terminal if you are worried about security. A MCP server is perfect to securely provide the LLM with some controlled power exactly because it can do nothing at all other than call tools that go through the MCP server and can therefore be scrutinized, audited and ensure credentials are not visible to the LLM.
    20. cbeach · · focus · HN ↗
      Also MCP allows exposition, which helps an autonomous agent understand the semantics of the API.

      That&#x27;s the killer feature from my PoV. I just point my agent at a URL and suddenly it knows when, why and how to use it.

      1. jimbokun · · focus · HN ↗
        Congratulations you reinvented man pages!
    21. anon84873628 · · focus · HN ↗
      The article also doesn&#x27;t contemplate the &quot;skill distribution problem&quot; which will be addressed by skills-over-mcp.

      With the plain ol&#x27; API solution, you still need some way for agents to fetch the instructions provided by the service. Of course there are answers for this, but they are not standardized.

      With MCP, all you have to do is provide the harness with a single URL and all context can be bootstrapped the same way for every service.

    22. miguelspizza · · focus · HN ↗
      The article misses the point of MCP but he is not wrong that it was a mistake (in some ways)

      The mistake of MCP was building it in such a way that it needed to be on a separate process from the API. The statefullness of MCP was such a massive detour for the industry that we will be cleaning up after it for years.

      Now that MCP is stateless we can start building what is actually useful: extending API’s for agents.

      When people ask me if they should do MCP today, I say absolutely. But because the Oauth protocol side of MCP is very good and is a net positive for all public API’s

      This is not a dig at MCP, the original vision of MCP was much different from how the community used it.

      1. cruffle_duffle · · focus · HN ↗
        &gt; The statefullness of MCP was such a massive detour for the industry that we will be cleaning up after it for years.

        I remember discovering this when i wrote my first MCP server. It was like &quot;huh? why would they do that? what use case did they have in mind?&quot;. We&#x27;ve spent decades making &quot;internet shit&quot; as stateless as possible on the backend because making it stateful is expensive and complex if you want to have any reasonable scalability. I mean good luck trying to host a stateful service on any kind of commodity serverless &quot;scale-to-zero&quot; infrastructure here in 2026.

        Maybe it&#x27;s because these AI-labs are used to statefulness. I mean LLM-based sessions are hugely stateful if you want any kind of reasonable caching to happen and caching is the only way you can economically scale out LLM&#x27;s. Seen from that perspective it kind of makes sense why they&#x27;d look at MCP and think &quot;hey, why not make this stateful on the backend as well&quot;. Statefullness just part of their DNA.

    23. kaoD · · focus · HN ↗
      All of that can be solved in better ways than MCP. 1+2+4 belongs to sandboxing. 3 to sandbox UIs. Ideally baked into the next generation OSs.

      MCP is the wrong abstraction for all of that. Skills are better as pluggable interfaces, and I predict[0] chat and agentic loops will converge eventually (Anthropic already did this correctly; OpenAI, it&#x27;s your turn) and skills marketplace will replace MCP in its current form.

      I see value in MCP, but it feels like a stopgap&#x2F;stepping stone.

      [0] Where &quot;predict&quot; = &quot;hope&quot;. The best solutions are often not the winners.

      1. tacoooooooo · · focus · HN ↗
        Skills are adjacent to MCP. They do not cover the same surface, in anyway. I don&#x27;t understand this argument at all (and I see lots of people making it, so enlighten me)

        I want my agent to be able to convert reliably between timezones. A skill does not solve this. It needs a deterministic tool it can call

        1. kaoD · · focus · HN ↗
          Skills are not only Markdown files. I often structure my skills as small Python scripts and the actual Markdown is only the skill front matter and maybe some brief documentation. You can even stick an OpenAPI schema or whatever you see fit.

          If you often need timezone conversion, sounds like a `timezones` skill exposing a few lines in a Python script. Boom. No MCP needed. No server needed. It&#x27;s just files, all the way down. If you find yourself operating with dates a lot maybe you need a `datetime` skill wrapping a bunch of tiny scripts. Fully deterministic, cheap on tokens, and you can even run them without an agent (shocking nowadays :P)

          As I identify repetitive actions I add (Claude adds) new scripts to the Skill to save tokens in the future, whereas MCP I&#x27;m at the mercy of the server provider. E.g. I have a Magic the Gathering skill with a bunch of tools to retrieve card databases, simulate hands, get card images...

          This article enlightened me: <a href="https:&#x2F;&#x2F;mariozechner.at&#x2F;posts&#x2F;2025-11-02-what-if-you-dont-need-mcp&#x2F;" rel="nofollow">https:&#x2F;&#x2F;mariozechner.at&#x2F;posts&#x2F;2025-11-02-what-if-you-dont-ne...

          This is why I don&#x27;t feel Skills are orthogonal. They feel like MCP on steroids since the scripts can be composed with Bash et al (huge battle-tested ecosystem, plenty in the training set)... and you don&#x27;t need crappy abstractions like &quot;resources&quot; (yes, that&#x27;s a thing in MCP) when the agent has a shell and a filesystem.

          I&#x27;ve used this pattern to great success. Nowadays I just share these `.skill` packages with my friends (I think they&#x27;re just a fancy ZIP file?)

          The only thing missing for me is credentials and sandboxing (see my GP post). I have my own ideas on how to solve this (and some of that Claude in cloud already solves for me), but it&#x27;s not easy (which is how MCP won).

          1. tacoooooooo · · focus · HN ↗
            &gt; If you often need timezone conversion, sounds like a `timezones` skill exposing a few lines in a Python script. Boom. No MCP needed. No server needed

            okay, but now my agent needs a coding environment &#x2F; sandbox.

            MCP (or tool use in general) solves this without that (extremely tenuous and expensive to do at scale in prd) requirement.

            The skill is totally orthogonal here--solving a totally separate problem

            1. kaoD · · focus · HN ↗
              I guess someone could expose the coding environment via MCP.
              1. tacoooooooo · · focus · HN ↗
                They could and code execution is actually exposed to the model as a tool!

                But if im running a customer support agent at scale, i&#x27;m not sure I want it to be able to write code. I do know I need it to be able to convert timezones though. (its also far more expensive &#x2F; token inefficient to have it write code each time to convert timezones rather to use a predefined tool I made an know works)

                1. kaoD · · focus · HN ↗
                  &gt; token inefficient to have it write code

                  It does not write code. It just calls my tool.

                  But I see your other points though.

    24. ramoz · · focus · HN ↗
      Even for coding agents. MCP is the only unified interface INTO harnesses. This pattern has not struck yet for most, but will soon in the coming months given the MCP spec. MCP has been about models calling tools., it is about to become some form of inverse and MCP will be the only actual way to integrate into the models. Simple example is sending an event to the model (today models have to poll)... these coming updates will cement MCP as permanent infrastructure.
    25. visarga · · focus · HN ↗
      What matters is local server or not. Using a remote server means exposure.
    26. paper2d · · focus · HN ↗
      Agree. MCP also helps in some esoteric use cases like interacting with legacy windows applications over COM. I created an MCP for Outlook 2019 desktop version and COM was the most straightforward way to let my agent interact with my mails for classification.
    27. ofirmakmal · · focus · HN ↗

      [dead]

    28. ransom1538 · · focus · HN ↗
      MCPs just misses what AI is. If you think MCP is a good idea you are confused what is going on. AI is beyond MCP. MCP is SOAP of AI.
    29. suroy · · focus · HN ↗

      [dead]

    30. wezabis · · focus · HN ↗

      [dead]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.