It's not just the agent understanding the API, it's locking down the access they have. If I want to give access to an internal service in specific ways that the API doesn't lock down then an MCP that offers very specific queries, with protective controls and transformations in place is very useful.
If one can build a MCP with proper protections, they can certainly do the same for their API/CLI/SDK.