|
|
|
|
|
by suzuridev
15 days ago
|
|
Small data point from the operator side: I run a tiny public MCP server, and when I finally turned on request logging, almost none of the traffic was what I expected. Mostly link-preview bots, keepalive pings, and scanners probing for wp-admin on an endpoint that isn't even WordPress. Made me realize most small MCP deployments probably have zero visibility into this — people ship a server and never look at what's actually hitting it. So the "you can't flag risky AI-generated commands without context" point resonates; at the low end the problem is even more basic, there's no context at all. |
|