4 ms·
Not sure. Our big org, banned MCPs because they are unsafe, and they have no way to enforce only certain MCPs (in github copilot).
by krzyk 7mo ago
Not sure.
Our big org, banned MCPs because they are unsafe, and they have no way to enforce only certain MCPs (in github copilot).
- thenewnewguy 7mo agoBut skills where you tell the LLM to shell out to some random command are safe? I'm not sure I understand the logic.
- toomuchtodo 7mo agoYou can control an execution context in a superior manner than a rando MCP server. MCP Security 2026: 30 CVEs in 60 Days - https://news.ycombinator.com/item?id=47356600 https://news.ycombinator.com/item?id=47356600 - March 2026 (securing this use case is a component of my work in a regulated industry and enterprise)
- newswasboring 7mo agoI think big companies already protect against random commands causing damage. Work laptops are tightly controlled for both networking and software.
- krzyk 7mo agoThey are not also, but I like that they didn't ban those, we can use agents thanks to that.
- yoyohello13 7mo agoWe only allow custom MCP servers.
- mbreese 7mo agoIsn’t it possible to proxy LLM communication and strip out unwanted MCP tool calls from conversations? I mean if you’re going to ban MCPs, you’re probably banning any CLI tooling too, right?
- thecopy 7mo agoShameless plug: im working on a product that aims to solve this: https://www.gatana.ai/ https://www.gatana.ai/
- brabel 7mo agoWho isn't?