Y
Hacker News
new
|
ask
|
show
|
jobs
by
maple3142
406 days ago
I think the reason is that MCP also works over a pipe (stdio), which does not need authentication.
1 comments
nightpool
405 days ago
It doesn't
need
it if this vulnerability is the only one you're worried about (remote websites), but it'd be nice to have it before letting it use e.g. your Github account. This is how VS Code extensions work, for example, and it's pretty nice
link