‹ BackHN Continuity

Thread

MCP was always a bad idea?

335 points · 331 comments · maharshi365

  1. simonw · · focus · HN ↗
    This article entirely misses the value that MCP brings today.

    Sure, there's almost no reason to use MCPs if you are running a full-blown terminal agent (Claude Code, Codex, Meta Muse, OpenClaw etc) with unfettered internet access - just let it call APIs directly.

    If you want to operate something that's less YOLO than that, you'll find yourself wanting:

    1. Control over exactly which external services it can access

    2. A way to handle authentication that doesn't allow the agent to directly access API keys

    3. A sensible UI to allow users to connect and authenticate further services

    4. Strong audit logging for what's going on

    MCP makes all of that so much easier to provide.

    Thinking MCP is obsolete because full coding agents don't need it misses out on all of the other things we might want to build.

    1. barrkel · · focus · HN ↗
      A CLI doing all this is still a better UI for the agent though.
      1. pixlmint · · focus · HN ↗
        What if I don't want my agent to have terminal access though? I get the feeling many people here simply never worked with smaller models, those will confuse cli args really quickly once context expands, and then you have no idea what damage they might do. With MCP's, they get just the access they actually need. Is the Principle of least privilege just not something we want to apply anymore?
        1. barrkel · · focus · HN ↗
          CLIs, run in a sandbox as tight as your preferred choosing, live in an ecosystem, where, via pipes and redirection, input and output can be easily manipulated. An agent can do similar things but more laboriously (and less token efficiently) via Python or similar but it would still live in a sandbox somewhere.

          Going without the sandbox means hobbling the LLM. It can do things directly but is less able to construct ad-hoc programs to deal with looping, conditionality, tame verbosity, connect tools together, and so on.

          It's a choice to not give the LLM an environment. As you say, it can be necessary if you're using dumb models. I don't find it particularly worth the trade most of the time.

          1. pixlmint · · focus · HN ↗
            If not even OpenAI can properly box in their models I definitely won't trust myself to do so with the very limited time available to me, and instead just use a standard that's already defined, and proven to work.
            1. barrkel · · focus · HN ↗
              By OpenAI, I presume you mean Irregular - these guys <a href="https:&#x2F;&#x2F;www.irregular.com&#x2F;about" rel="nofollow">https:&#x2F;&#x2F;www.irregular.com&#x2F;about ?

              These guys are the common factor, the guys running the evals that let all the AI agents out, it looks like.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.