Remix.run Logo
behnamoh 4 days ago

I've disabled all MCP servers on my machine until this security nightmare is fully resolved.

MCP is not that elegant anyway, looks more like a hack and ignores decades of web dev/security best practices.

mehdibl 4 days ago | parent [-]

What the issues, if you use quality MCP tools?

Also MCP is only transport and there is a lot of mixup to blame the MCP, as most of the prompt injection and similar come from the "TOOLS" behind the MCP. Not MCP as it self here.

Seem this security hype forget one key point: Supply chain & trusted sources.

What is the risk running an MCP server from Microsoft? Or Anthropic? Google?

All the reports explain attacks using flawed MCP servers, so from sources that either are malicious or compromised.

agoodusername63 4 days ago | parent [-]

> What the issues, if you use quality MCP tools?

Really doesn't help when discovery of "quality" MCP tools, whatever that means, is so difficult.