Skip to content Skip to footer
Everything wrong with MCP by sshh12

Everything wrong with MCP by sshh12

10 Comments

  • Post Author
    cratermoon
    Posted April 14, 2025 at 12:11 am

    "Authentication is tricky and so it was very fair that the designers chose not to include it in the first version of the protocol."

    No, it's not fair at all.
    You can't add security afterwards like spreading icing on baked cake.
    If you forgot to add sugar to the cake batter,
    there's not enough buttercream in the world to fix it.

  • Post Author
    seuros
    Posted April 14, 2025 at 12:41 am

    Did you read the spec ? Everything you said is already a recommendation.

  • Post Author
    klntsky
    Posted April 14, 2025 at 12:56 am

    MCP is a dead end for chatbots. Building valuable workflows requires more than tool calling, most importantly, understanding the context of a conversation to adjust the tools dynamically.

  • Post Author
    totaldude87
    Posted April 14, 2025 at 1:07 am

    isnt langchain doing the exact same thing? (sorry ai noob here)

  • Post Author
    behnamoh
    Posted April 14, 2025 at 1:09 am

    Yeah, I don't feel comfortable downloading tiny server programs from random devs on the internet to give my LLM client apps extra "tools". I can LuLu or LittleSnitch regular apps but not these ones.

  • Post Author
    jwpapi
    Posted April 14, 2025 at 1:20 am

    I have read 30 MCP articles now and I still don’t understand why we not just use API?

  • Post Author
    dend
    Posted April 14, 2025 at 1:53 am

    Coordinator of the authorization RFC linked in this post[1].

    The protocol is in very, very early stages and there are a lot of things that still need to be figured out. That being said, I can commend Anthropic on being very open to listening to the community and acting on the feedback. The authorization spec RFC, for example, is a coordinated effort between security experts at Microsoft (my employer), Arcade, Hellō, Auth0/Okta, Stytch, Descope, and quite a few others. The folks at Anthropic set the foundation and welcomed others to help build on it. It will mature and get better.

    [1]: https://github.com/modelcontextprotocol/modelcontextprotocol…

  • Post Author
    rglover
    Posted April 14, 2025 at 2:00 am

    Yet another piece of rushed technology that's being heralded as "the way" which will most certainly be discarded when the next hype-able acronym comes along.

    The only upside to these technologies being shotgun implemented and promoted is that they'll inevitably lead to a failure that can't be pushed under the rug (and will irreversibly damage the credibility of AI usage in business).

  • Post Author
    mehdibl
    Posted April 14, 2025 at 2:21 am

    MCP have a BAD UI?

    MCP is not a UI. Seem someone here quite confused about what is MCP.

    MCP have no security?
    Someone don't know that stdio is secure and over SSE/HTTP there was already specs:
    https://modelcontextprotocol.io/specification/2025-03-26/bas….

    MCP can run malicious code?
    Apply to any app you download. How this is the MCP issue? Happen in vscode extensions. NPM libs. But blame MCP.

    MCP transmits unstructured text by design?

    This is totally funny. It's the tool that decide what to respond. Annd the dialogue is quite

    I start feeling this post is a troll.

    I stopped reading and even worth continuing over prompt injection and so on.

  • Post Author
    sunpazed
    Posted April 14, 2025 at 2:25 am

    Let’s remind ourselves that MCP was announced to the world in November 2024, only 4 short months ago. The RFC is actively being worked on and evolving.

Leave a comment

In the Shadows of Innovation”

© 2025 HackTech.info. All Rights Reserved.

Sign Up to Our Newsletter

Be the first to know the latest updates

Whoops, you're not connected to Mailchimp. You need to enter a valid Mailchimp API key.