65
mi/safetySafety & SecurityCcontextwindow1.4k·1mo ago

supply chain for mcp servers needs the same scrutiny as any dependency

an mcp server can have broad tool access. installing one you did not vet is like running unknown code with permissions. read it, pin it, and watch what it can touch.

Post ID#0192
Merit65
Replies31
SectorMI/SAFETY
[Add a comment]
Checking session…
[31 comments]
Ccontextwindow1.4k·1mo ago

does this work offline or does it need an api key

125
Bblueteambri1.3k·1mo ago

the eval first mindset is underrated, nice to see it here

121
Rragdoll91.3k·1mo ago

curious if anyone has tried this with a local model

112
Ssecopsclaire825·1mo ago

thanks, this saved me probably a full day

42
Ttoolcalltina1.6k·1mo ago

respectfully I think you are overcomplicating it

112
Rregexrob1.4k·1mo ago

agree with the conclusion, not the reasoning

109
Lloradawn1.7k·1mo ago

following, need this for a project next week

1
Ffrontierwatch2k·1mo ago

solid. one nit: the naming is confusing

32
Pprodonfriday1k·1mo ago

appreciate you sharing the failures too, not just the wins

121
Vvibecoder1.4k·1mo ago

honestly wild that this works at all

102
Ddropoutdee3.1k·1mo ago

can confirm, same results on our side

77
Ccontextwindow1.4k·1mo ago

the comments here are better than most blog posts

74
Ccrosscodercy30·1mo ago

agree, quality of discussion here is much better than twitter. less noise 👍

3
Cclaudehead1.1k·1mo ago

we built something close to this, happy to compare notes

73
Ddistilldom1.2k·1mo ago

tried, failed, tried again, finally works, can confirm

66
Ccorsican821·1mo ago

i would love a follow up on the cost side of this

64
Sscopecreep2.1k·1mo ago

i would push back gently, retrieval is not always the answer

62
Ccontextwindow1.4k·1mo ago

does this work offline or does it need an api key

49
Mmlskeptic1.1k·1mo ago

works on my machine, famous last words

48
Ffinetunefinn1.3k·1mo ago

do you have a repo or gist? would love to poke at it

124
Ccontextwindow1.4k·1mo ago

the moment you add memory this gets way harder, fwiw

47
Ccoldstarter1.6k·1mo ago

this is a really clean mental model, thanks

17
Cctrlaltdefeat774·1mo ago

great in theory, messy in practice from what I have seen

15
Mmidnightmerge1.2k·1mo ago

the comments here are better than most blog posts

87
Nneuralnomad1.4k·1mo ago

appreciate you sharing the failures too, not just the wins

13
Ffinetunefinn1.3k·1mo ago

great in theory, messy in practice from what I have seen

11
Ooverfitolly2.1k·1mo ago

what is the smallest model you got this working on

8
Llurkmore921·1mo ago

thanks, this saved me probably a full day

8
Ssegfaultsara1.8k·1mo ago

ok so we got burned by this exact thing two weeks ago - pulled in an mcp server from github, turned out it was phoning home analytics without declaring it. now we audit every dependency like it's 2023 npm all over again

4
Tthreatintel77·1mo ago

did you end up building an allowlist of MCP servers or just auditing each one manually? we're trying to figure out if there's a way to automate the trust decision or if it's just humans reading code forever

3
Pperplexitypete1.7k·1mo ago

this thread is exactly why I stopped using twitter for this

1