{"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"mcp-what-is-it-why-it-matters-and-why-caution-is-warranted-in-2025","__idx":0},"children":["MCP: what is it, why it matters, and why caution is warranted in 2025"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In late 2024, ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://www.anthropic.com/news/model-context-protocol"},"children":["Anthropic introduced"]}," the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Model Context Protocol (MCP)"]}," —"," ","a new way for AI agents to interact with tools and data through standardized interfaces."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["MCP has generated excitement across developer communities, especially for its promise to streamline how agents connect to external services."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["But it’s also sparked debate, including among API experts and engineering leaders, about whether it’s mature or secure enough for wide adoption."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In this post, we’ll explain what MCP does, where it’s useful, and where it falls short — especially for developers trying to build reliable and secure"," ","AI applications and systems."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"what-mcp-is-solving-for","__idx":1},"children":["What MCP is solving for"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Today’s AI agents are limited by how they interact with APIs and external tools."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Most integrations require custom code, brittle scripts, or predefined workflows."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["MCP proposes a reusable approach for agent-tool interaction via a standard JSON"," ","interface."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["MCP aims to make it easier to:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Expose internal tools to agents without custom wrappers"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Standardize how agents interact with APIs or file systems"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Create agent workflows that chain together multiple tools"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This reduces integration overhead and allow developers to plug new tools into agent systems faster."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"whats-inside-mcp","__idx":2},"children":["What's inside MCP?"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["At its core, MCP follows a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["client-server architecture"]},":"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["MCP client"]},", often embedded inside the AI agent, sends requests."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["MCP server"]}," exposes tools or APIs in a consistent, machine-readable way."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Communication happens over ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["JSON-RPC 2.0"]},", with calls like ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["read_file"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["run_tool"]},", etc."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["MCP is ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["model-agnostic"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["open-source"]},", which makes it appealing to developers trying to standardize"," ","their tool interface layer."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"the-real-world-reality-of-mcp","__idx":3},"children":["The real-world reality of MCP"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Despite the appealing goals, some in the developer and API ecosystem remain cautious — and for good reason."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"1-loose-structure-with-no-formal-governing-body","__idx":4},"children":["1. Loose structure with no formal governing body"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["When we first reviewed MCP, we noted that it wasn't a formal protocol specification in the expected sense."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Many of the early discussions lived across example code and GitHub discussions, making it difficult to sort through."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Additionally, it's important to note MCP's governance structure and standardization process is still evolving under"," ","the leadership of Anthropic, and the future governance structure is uncertain."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"2-permissions-and-security-risk","__idx":5},"children":["2. Permissions and security risk"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["One major concern came to light in a ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://github.com/modelcontext/protocol/issues/18"},"children":["recent GitHub issue"]},","," ","where a misconfigured MCP server exposed internal tools to broader access than intended."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This wasn’t classic prompt injection — it was a permissions scope issue that stemmed from how tools were described and invoked by agents."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Developers rushing to add MCP to their systems often don’t fully isolate or sandbox access."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This creates a real risk, especially when AI agents are granted open-ended access to internal operations."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"3-questionable-usefulness-in-many-use-cases","__idx":6},"children":["3. Questionable usefulness in many use cases"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In practice, over half of MCP tools today just expose documentation or basic static data."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Some experts argue that simpler alternatives already exist:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Direct HTML parsing"]}," by LLMs"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["LLMs.txt"]}," (a markdown-based context file format)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["OpenAPI + cURL"]}," for structured endpoint interaction"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["These approaches are often more efficient and require fewer moving parts."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"what-were-keeping-an-eye-on-with-mcp","__idx":7},"children":["What we're keeping an eye on with MCP"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["We expect more innovation to happen in this space, and we're keeping a close eye on it."," ","Here's what's most interesting to us today:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Enterprise automation"]},", where internal tools are otherwise hard to expose via APIs"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["AI-assisted coding"]},", where context-aware tools can be dynamically invoked"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["AI agent frameworks and low-code agent builders"]},", like ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://mastra.ai/blog/mastra-mcp"},"children":["Mastra"]}," ","and ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://www.gumloop.com/blog/announcing-gumcp"},"children":["Gumloop"]}," where support of MCP is enabling faster,"," ","more dynamic agent-powered applications."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Additional emerging protocols"]},", like CopilotKit's ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://github.com/ag-ui-protocol/ag-ui"},"children":["AG-UI"]}," for"," ","making user-agent interaction more accessible for the frontend, and"," ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://developers.googleblog.com/en/a2a-a-new-era-of-agent-interoperability/"},"children":["Google's A2A protocol"]}," ","for agents interacting with other agents."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"should-you-use-mcp-today","__idx":8},"children":["Should you use MCP today?"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["We're hopeful to see MCP and other emerging protocols continue to mature as they're more widely adopted."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["All things considered, if you're a developer working on AI agent infrastructure, MCP is promising."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["As with any emerging technological development, it’s important to treat it with an ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["experimental"]}," ","mindset."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["MCP is still evolving, security practices are immature, and real-world value is still being proven"," ","out at meaningful scale."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In our view, MCP needs more of the rigor we've been applying to API specs and standards over the"," ","last two decades."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Before adopting it, we recommend developers:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Read the full spec"]}," (",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://modelcontextprotocol.io"},"children":["modelcontextprotocol.io"]},")"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Review security boundaries carefully"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Don’t expose sensitive tools without strict permission controls"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Consider if direct integrations are more practical"]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"final-thoughts","__idx":9},"children":["Final thoughts"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["MCP is an ambitious attempt to rethink how AI agents interact with the world, and that’s worth exploring."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["We encourage developers to test, share feedback, and improve the ecosystem - and to go in with eyes open."]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"faq","__idx":10},"children":["FAQ"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["How is MCP different from OpenAPI?"]},{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]},"MCP is runtime-focused — agents call tools dynamically. OpenAPI is more declarative and often used to generate client libraries or documentation."," ","The two can complement each other."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Is MCP secure?"]},{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]},"It depends heavily on how it’s implemented. The protocol itself doesn’t enforce access control — that’s up to the developer."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["What happened with the GitHub security issue?"]},{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]},"A ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://github.com/modelcontext/protocol/issues/18"},"children":["reported case"]}," showed that an MCP server granted broader access than intended.",{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]},"The root issue was a lack of scoped permissions in how tools were defined and invoked."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Is MCP necessary?"]},{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]},"Not always. For many use cases, standard API calls or context injection via other formats may be more practical."]}]},"frontmatter":{"template":"../@theme/templates/BlogPost","title":"MCP: what it is, why it matters, and why caution is warranted in 2025","description":"Explore the pros and cons of Model Context Protocol (MCP), an emerging standard for AI agent interaction.","seo":{"title":"MCP: what is it, why it matters, and why caution is warranted in 2025","description":"Explore the pros and cons of Model Context Protocol (MCP), an emerging standard for AI agent interaction."},"image":"mcp-header.png","author":"adam-altman","publishedDate":"2025-07-15","categories":["api-specifications:contract-patterns"]},"tagList":[],"title":"MCP: what is it, why it matters, and why caution is warranted in 2025","lastModified":"2025-11-24T15:40:38.000Z"}