Comment by arjunchint

7 months ago

> You say it like it's a bad thing. But ideally this also brings clarity & purpose to your own API design too! Ideally there is conjunct purpose! And perhaps shared mechanism!

I update my website multiple times a day. I want to have as much decoupling as possible. Everytime I update internal API, I dont want to think of having to also update this WebMCP config.

Basically I have to put in work setting up WebMCP, so that Google can have a better agent that disintermediates my site.

> Trying to keep users from seeing what data they want is, generally, not something I favor.

This is literally the whole cat and mouse game of scraping and web automation, sites clearly want to protect their moat and differentiators. LinkedIn/X/Google literally sue people for scraping, I don't think they themselves are going to package all this data as a WebMCP endpoint for easy scraping.

Regardless of your preferences/ideals, the ecosystem is not going to change overnight due to hype about agents.

> Your site running its own agent is going to take a lot of resources

A lot of sites already expose chatbots, its trivial to rate limit and captcha on abuse detection

If you have a nice core architecture, you can just have WebMCP expose the core directly. Folks using GraphQL or some rpc system might be able to have an always in sync system automatically.

> so that Google can have a better agent that disintermediates my site.

This isn't disintermediated by or for Google.

The beneficiary here is the user, who gets to do what they want with their agent directly. I realize the idea of users doing what they want makes a lot of site owners nervous and scared, but RFC8890, the internet is for end users: site's attempts to coral and control users is interpreted as damage and routed around. This is a moral and ethical specification that actually helps users do what they want to do. Without Google or perhaps 3rd party scraping bots having to be involved.

> A lot of sites already expose chatbots,

Which very often are pretty dumb menu trees. Or sometimes have some data services or capabilities they can access. But is a crappy ultra-slim model going to make your users happy? Are they going to get what they want from this chatbot? Is it going to help them do what they want? Is it going to work with their calendering app or their email app, to get the job done? I think what you are saying is once again: fuck the user, take my crappy bad experience that sucks, and deal with it. No one likes chatbots. They like their agents.

> its trivial to rate limit and captcha on abuse detection

What if the user is there, but asks computationally complex questions? There's so so many examples of prompt hijacking, of break outs, of ways to fool AIs. Turns out that if you add some punct.uation or spa ces in words, prompt injection attacks tend to be far more effective. That's just one of thousands of things we've found for attacking LLMs.

The idea that you can just rate limit and captcha your way out of users using an agent you are hosting has to be a joke, right?

Nothing about anything you've said makes me think you have any respect or desire to let users have a good experience.