‹ BackHN Continuity

Thread

MCP was always a bad idea?

335 points · 331 comments · maharshi365

  1. honoluluxyz · · focus · HN ↗
    It seems like OP needs to provide a solution to hiding the credentials from the model in order to suggest CLI-mode only, and also a solution to the problem of agents without shell access.
    1. maharshi365 · · focus · HN ↗
      I've been thinking about this. Technically mcp auth is also not secure, the keys are in env or in file and accessible to the agent.

      I think something like infiscial ai proxy could be useful here. Never store the creds on device.

      1. lowbloodsugar · · focus · HN ↗
        > I've been thinking about this. Technically mcp auth is also not secure, the keys are in env or in file and accessible to the agent.

        This is the biggest problems with most “sandboxes”. Some people aren’t even running a sandbox. But even the best have a big problem: APIs where GET verbs provide write features.

        This is the value of MCP: minimize the surface to known APIs and identify read-only from mutating so I can trust, approve or block. The MCP server, in this case, does NOT run in an environment that the read/write or shell can see.

        1. agentdev001 · · focus · HN ↗
          Something like openshell is the answer here, to the point of GET being a write. The gap left here is what, imo, is something that MCP fits nicely- which is serving non-http resources with restrictions: databases for example.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.