If one can build a MCP with proper protections, they can certainly do the same for their API/CLI/SDK.
I can build a local MCP that gives restricted access to an API which I have no control over.
I can build a local MCP that gives restricted access to an API which I have no control over.