logoalt Hacker News

jimbokunyesterday at 2:38 PM3 repliesview on HN

The service itself needs to control what the agent can access.

Relying on an intermediary to provide access controls, and that agents will never access the service directly, seems dangerous and naive.


Replies

Tractor8626yesterday at 6:04 PM

Agent doesn't have api key to access service directly

anon84873628yesterday at 3:30 PM

And it's easy for the service to do that by hosting a remote MCP server.

jayd16yesterday at 3:19 PM

What? Why? More is more but you're arguing a security proxy is a dangerous and naive pattern?