‹ BackHN Continuity

Thread

You said no MCP

682 points · 362 comments · yarapavan

  1. wren6991 · · focus · HN ↗
    > And while we could have just wired up the metadata to enable better MCP extensions, we also think that MCP with Codemode solves quite a few of the issues that it traditionally had.

    There's just something that bothers me about this. Normally if LLMs want to compose multiple operations, they have the perfect tool for this: bash, or whatever other OS shell is available. It's why I was always confused by Codemode-type constructs for direct chaining of tool calls; see also the way highly-RL'd modern models will fall back to sed or python for complex file edits.

    It seems like Codemode is raised here as the perfect tool for chaining or composing MCPs, but isn't that backwards? LLMs are already given the perfect tool for that, and the problem is that MCPs aren't exposed to that tool.

    1. hobofan · · focus · HN ↗
      > Normally if LLMs want to compose multiple operations, they have the perfect tool for this: bash, or whatever other OS shell is available.

      I many scenarios, e.g. running the harness server-side, as is the case for chat interfaces, you don't really want to expose OS shell access as that opens up a huge security attack surface.

      1. otabdeveloper4 · · focus · HN ↗
        You can give the LLM a bash without giving it the full /usr/bin.

        That's been a trivially solved problem for decades.

        1. hobofan · · focus · HN ↗
          That has been one of the most common exploits for decades.
          1. otabdeveloper4 · · focus · HN ↗
            Yes, and also MCP does literally nothing to prevent these sorts of exploits.

            Like I said, AI bros vibecoding slop because they literally have no clue what they're doing.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.