‹ BackHN Continuity

Thread

MCP was always a bad idea?

335 points · 331 comments · maharshi365

  1. honoluluxyz · · focus · HN ↗
    It seems like OP needs to provide a solution to hiding the credentials from the model in order to suggest CLI-mode only, and also a solution to the problem of agents without shell access.
    1. darkamaul · · focus · HN ↗
      In coop [0], a VM manager we developped to sandbox agent usage (i.e. give them freedom to do their stuff, but in an isolated environment from your main machine), we try to solve this by having an intermediate proxy (coop-proxy).

      Instead of forwarding ANTHROPIC_API_KEY / OPENAI_API_KEY into the guest, we simply run a reverse-proxy within the VM that replace a constant-time token with the real API key on the host.

      Works well enough in practice

      [0] <a href="https:&#x2F;&#x2F;github.com&#x2F;trailofbits&#x2F;coop" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;trailofbits&#x2F;coop

      1. drejt · · focus · HN ↗

        [dead]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.