▲ | mehdibl 4 days ago | ||||||||||||||||||||||
There is confusion. 1. Not all MCP tools connect to the web or fetch emails. So the shortcut all MCP's are doomed is also the wrong way to adress this. 2. Issue is with MCP with untrusted external sources like web/email that need sanitization like we do with web forms. 3. A lot of warning point bad MCP's! But that apply to any code you might download/ use from the internet. Any package can be flawed. Are you audit them all? So yeah, on my side I feel this security frenzy over MCP is over hyped. VS the real risk and there is a lot of shortcuts, masking a key issue that is supply chain as an MCP owned issue here and I see that in so many doom comment here. | |||||||||||||||||||||||
▲ | esseph 4 days ago | parent [-] | ||||||||||||||||||||||
This is a blanket statement, just an anecdote from my career. Every developer I have ever met that wasn't in the security space underestimates security problems. Every one. YMMV | |||||||||||||||||||||||
|