Comment by asdev
Comment by asdev a day ago
You don't need MCP you just need function calling
Comment by asdev a day ago
You don't need MCP you just need function calling
Remote MCP servers can do prompt injection that instruct your local agent to do something else other than only the expected tool call. https://embracethered.com/blog/posts/2025/model-context-prot...
That flaw isn't introduced by the MCP server necessarily it can already be present in the API data it returns, you will never be able to protect yourself against someone injecting a malicious prompt that calls your code eval tool to open up a reverse shell on your MacBook Pro.
That is being done as a stop gap until official servers are released. Ideally you are writing a server for your own product/service, or custom local work.
i.e. I wrote a server for water.gov to pull the river height prediction nearby for the next 24hr. This helps the campground welcome message writing tool craft a better welcome message.
Sure that could be a plain tool call, but why not make it portable into any AI service.
Is there a better “universal” or standard framework to do itv
Yeah, but there is a distinct advantage to using a standard.
Suppose you want your agent to use postgres or git or even file modification. You write your code to use MCP and your backend is already available. It's code you don't have to write.