‹ BackHN Continuity

Thread

You said no MCP

682 points · 362 comments · yarapavan

  1. alin23 · · focus · HN ↗
    Lately I found MCP to be much more than a coding tool. For example, I implemented it in my more complex macOS apps [0] like rcmd, Clop, Lunar, so they can be configured by natural language.

    So even with a local Qwen and Pi you can now say things like:

        Set up Clop to optimise any PNG that I drop in my website assets folder and convert to a webp with the same name near it
    
        Get Crank to start Time Machine backups immediately when I connect my HDD and notify me when the backup is done.
    
        I want to be able to hold rcmd and fuzzy search and focus cmux agent panes
    
    BetterTouchTool has a great MCP which can create native SwiftUI views and bind them to hotkeys, trackpad gestures etc. It can leverage its immense macOS automation tools and private APIs to let agents do Computer Use.

    You would need a much more capable coding model to code those tools from scratch and get the same fail-safe logic that the apps have honed over the years.

    Like, since MCP, Crank [1] has fully replaced my use of crontab, launchd, scattered scripts I run once a week. Not that it could not do that before, but it's so much simpler now to just describe the automation and have it happen reliably and visible in the UI. The friction is gone.

    [0] <a href="https:&#x2F;&#x2F;reddit.com&#x2F;r&#x2F;macapps&#x2F;comments&#x2F;1wkv0dy&#x2F;mcp_in_macos_apps_are_they_useful_for_you&#x2F;" rel="nofollow">https:&#x2F;&#x2F;reddit.com&#x2F;r&#x2F;macapps&#x2F;comments&#x2F;1wkv0dy&#x2F;mcp_in_macos_a...

    [1] <a href="https:&#x2F;&#x2F;lowtechguys.com&#x2F;crank" rel="nofollow">https:&#x2F;&#x2F;lowtechguys.com&#x2F;crank

    1. mike-cardwell · · focus · HN ↗
      I gave claude an API key for Home Assistant. I can tell it to create dashboards, set up automations, diagnose problems etc, all using natural language. No MCP needed.

      Yesterday I received a new thermometer for my aquarium to replace an old broken one. Both were bluetooth, but different models. I just told claude &quot;I&#x27;m going to set up up my new bluetooth thermometer for my fish tank in a few minutes, keep an eye out for it and replace the old broken one with it in Home Assistant&quot; and then walked away and put a battery in it and put it in my aquarium.

      When I came back it had found it, replaced all my existing entities for the broken one with the new one, and verified it was all working with my existing graphs and automations.

      1. FrinkleFrankle · · focus · HN ↗
        MCP is a tool more for security than anything else. If you give your agents access to an API key, there&#x27;s a chance they can accidentally or maliciously leak that key. If the MCP server has access to the keys instead, it takes that possibility away. That&#x27;s not always something you need to care about, but it is very important for some people&#x27;s threat model.
        1. cheema33 · · focus · HN ↗
          &gt; MCP is a tool more for security than anything else.

          The agent can get to the resource through the MCP server or using API key. I personally do not see the benefit MCP is providing here. Sure you can reduce the exposed surface at MCP layer, but I do that at the API layer. I don&#x27;t need to add another layer here.

          I can kinda understand if you do not have control of the API layer and&#x2F;or you have to expose the API layer to the public Internet as well. Most of the time that is not the case for me.

          1. anamexis · · focus · HN ↗
            The idea is that with an MCP, the agent doesn’t have access to any credentials. It can’t leak an API key.
            1. spellboots · · focus · HN ↗
              There are many ways to do this without using mcp, for example one of the many proxy servers that inject the token into requests. I use a custom solution that redacts all secrets to agent transcripts before the agent sees them in a hook.

              I find it way better to be able to confidently tell agents to use CLIs than worrying about partially implemented mcps that need configuration and are often yolo’d with npx @latest anyway

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.