3 ms·
Hah, I made that same point last December: https://simonwillison.net/2025/Dec/31/the-year-in-llms/#the-only-year-of-mcp https://simonwillison.net/2025/Dec/31/t
by simonw 12d ago
Hah, I made that same point last December: https://simonwillison.net/2025/Dec/31/the-year-in-llms/#the-only-year-of-mcp https://simonwillison.net/2025/Dec/31/the-year-in-llms/#the-...
> For a while it also felt like MCP was a convenient answer for companies that were under pressure to have “an AI strategy” but didn’t really know how to do that.
I've since come back to MCPs, because I want to build my own agents without first having to solve the problem of effectively sandboxing Bash.
- mikeocool 12d agoYeah, from a design perspective MCP upsets me, because it’s a poorly designed standard and creating a good one could have been much easier. But you’re right, since clients don’t have a nicely sandboxed “make api request” tool, it’s basically the way to go for a lot of use cases.
- rsalus 12d agoI think the new 07-28 spec is quite decent
- agentdev001 12d ago"without first having to solve the problem of effectively sandboxing Bash" Hopefully this is easier as time goes on. Of course- also policy on the egress
- otabdeveloper4 12d ago> without first having to solve the problem of effectively sandboxing Bash "Sandboxing bash" is a problem that has been solved a zillion years ago already. Take your pick of any of the dozens of battle-proven solutions.
- simonw 11d agoWhich solution do you recommend? Bonus points if it's available on both macOS and Linux and doesn't come from a random unmaintained GitHub repository with a note in the README that says "don't run this in production".
- Sohcahtoa82 11d ago"Battle-proven" until an LLM decides it really needs to escape the sandbox you put it in and eventually succeeds. For personal work, I run Codex in a VM that contains only what's necessary to do software development. Could it escape the VM? Sure, if there's a zero-day in VMWare Workstation. Yeah, I'm using a pile driver when I really probably just need a hammer, but I've seen too many horror stories, and I don't trust guard rails. Even if there was an option to limit Bash calls to read-only operations, I would be 0% surprised to eventually run into "You're absolutely right! `rm -rf / --no-preserve-root` was a write operation! That's totally on me."
- indymike 12d agoMCP is one of those things that is "too good enough".
- jimbokun 11d agoUnderstood but it seems like effectively sandboxing cash is a very very important problem for the industry to solve! Would be a much more robust and general solution of the problem of controlling and auditing agentic access to sensitive information.
- tadfisher 11d agoIt's such an important problem that it is sucking all available VC money into an exponentially-growing number of startups promising to make sandboxed agents safe and usable. In other news, MCP exists.
- JambalayaJimbo 11d agoWhat do you mean by sandboxing bash? Isn’t this about just having a tool like curl or Postman? Implanting an MCP client in your agent code isn’t all that different from calling requests or whatever
- simonw 11d agoI mean the ability to have an agent run commands in a Bash shell without allowing them access to any file or environment variable visible to the user on that computer, and without allowing them uncontrolled internet access.