4 ms·
We're keeping an unofficial allow list at work. Basically just major software companies only. Third party mcp servers at this point are basically just attack
by smrtinsert 1y ago
We're keeping an unofficial allow list at work. Basically just major software companies only. Third party mcp servers at this point are basically just attack vectors. How do you even vet them continuously?
Honestly vetting MCP seems like a YC company in and of itself.
- wirehack 1y agoWe build our MCP servers ourselves and many of them are open source. You can check out our github repo.
- mikestorrent 1y agoYeah, we face this issue as well. Folks are super keen to just download code from random people's githubs and run it with their credentials and grant it access to contexts that have all kinds of abilities to cause damage if there was ever a supply chain attack.