Comment by Miyamura80
4 days ago
> MCP is a tool more for security than anything else. +1 to this; API keys mean: a) Your agents are overprivileged by default b) Your API key is more likely to get into logs and pre-training / leaked as FrinkleFrankie mentioned c) You can't manage it centrally with granular tool policies in Enterprises. (e.g. "you're not allowed to read slack channel for #finances")
Also, you can always collapse MCP to CLI, so MCP as auth/security middleware makes a lot of sense.
PoC of MCP -> CLI: https://github.com/edison-watch/cli
No comments yet
Contribute on Hacker News ↗