4 ms·
This argument always sounds like two crowds shouting past each other. Are you a solo developer, are you fully in control of your environment, are you focused o
by tow21 6mo ago
This argument always sounds like two crowds shouting past each other.
Are you a solo developer, are you fully in control of your environment, are you focused on productivity and extremely tight feedback loops, do you have a high tolerance for risk: you should probably use CLIs. MCPs will just irritate you.
Are you trying to work together with multiple people at organizational scale and alignment is a problem; are you working in a range of environments which need controls and management, do you have a more defensive risk tolerance ... then by the time you wrap CLIs into a form that are suitable you will have reinvented a version of the MCP protocol. You might as well just use MCP in the first place.
Aside - yes, MCP in its current iteration is fairly greedy in its context usage, but that's very obviously going to be fixed with various progressive-disclosure approaches as the spec develops.
- joshwarwick15 6mo agoContext usage is a client problem - progressive disclosure can be implemented without any spec changes (Claude/code has this built in for example). That being said the examples for creating a client could be massively expanded to show how to do this well
- exossho 6mo agoagree I don't get this discussion anyways Those are two different things, and actually they work well together..
- pavelbuild 6mo ago[dead]
- theshrike79 6mo agoIn an organisation we can’t limit MCP access. It’s all or nothing. Everything the user can touch, the MCP can touch. We can trust humans not to do stupid things. They might accidentally delete maybe two items by fat-fingering the UI. An Agent can delete a thousand items in a second while doing 30 other things. With bespoke CLI tools we can configure them so that they cannot access anything except specific resources, limiting the possible blast radius considerably.
- jjice 6mo ago> In an organisation we can’t limit MCP access. Why not? I'd imagine that you could grant specific permissions upon MCP auth. Is the issue that the services you're using don't support those controls, or is it something else?
- theshrike79 6mo agoI haven’t seen a single major MCP provider that would let us limit access properly Miro, Linear, Notion etc… They just casually let the MCP do anything the user can and access everything. For example: Legal is never letting us connect to Notion MCP as is because it has stuff that must NEVER reach any LLM even if they pinky swear not to train with our stuff. -> thus, hard deterministic limits are non-negotiable.
- pjm331 6mo agoit's straightforward to spin up a custom MCP wrapper around any API with whatever access controls you want the only time i reach for official MCP is when they offer features that are not available via API - and this annoys me to no end (looking at you Figma, Hex)
- theshrike79 6mo agoThat’s what we’re doing, but it’s annoying. Why can’t they just let us limit access for the official MCP easily?
- jjice 6mo agoAgreed. Sounds like a failure of the services, but not MCP. Can't believe in 2026 we don't have better permissions on systems like this.
- pojzon 6mo ago“Communism can work we just did not see a good implementation of it”. If majority of implementations fail at it -> protocol is defined incorrectly. With security first approach it would not be the case.
- deleted 6mo ago[deleted]