Skip Navigation

Leak confirms OpenAI's ChatGPT will integrate MCP

www.bleepingcomputer.com

Just a moment...

An interesting development, but I doubt it'll be a good thing, especially at first. This looks like the kind of thing that will be an entirely new threat vector and a huge liability, even when used in the most secure way possible, but especially when used in a haphazard way that we'll certainly see from some of the early adoptors.

Just because you can do a thing, does not mean that you should.

I almost feel like this should have an NSFW tag because this will almost certainly not be safe for work.

Edit: looks like the article preview is failing to load... I'll try to fix it. ... Nope. Couldn't fix.

9 comments
  • The connectors are still optional.

    Haphazard code is not a new thing. Some statistics claim that almost 50% of "vibe coded" websites have security flaws. It's not much different from the old "12345" password, or the "qwerty" one (not naming names, but have known people using it on government infrastructure), or the "who'd want to hack us?" attitude.

    MCP is the right step forward, nothing wrong with it on itself.

    People disregarding basic security practices... will suffer, as always... and I don't really see anything wrong with that either. Too bad for those forced to rely on them, but that's a legislative and regulatory issue, vote accordingly.

    I would still be extremely hesitant of enabling any MCP connector on non-local model instances. People need to push harder for local and on-prem AI, it's the only sane way forward.

    • I really think we just need to move on from this AI craze.

      We don't have a general intelligence. We may never have a general intelligence.

      Keep using AI for what it's good for: statistics based decision making. Stop trying to use AI for designing solutions; it's not built for that because that requires reasoning which is something AI cannot do no matter how much snake oil society has been sold.

      You want to use it for generating a picture, a poem, or a song ... fine, it's at least good at that because it doesn't have to solve anything using facts, making stuff up IS the goal.

      • "AI" has been a buzzword basically forever, it's a moving target of "simulates some human behavior". Every time it does that, we call it an "algorithm" and move the goalpost for "true AI".

        I don't know if we'll ever get AGI, or even want to, or be able to tell if we get a post-AGI. Right now, "AI" stands for something between LLMs, and Agents with an LLM core. Agents benefit from MCP, so that's good for AI Agents.

        We can offload some basic reasoning tasks to an LLM Agent, MCP connectors allow them to interact with other services, even other agents. A lot of knowledge is locked in the deep web, and in corporate knowledge bases. The way to access those safely, will be through agents deciding which knowledge to reveal. MCP is aiming to become the new web protocol for "AI"s, no less no more.

        Some careless people will get burned, the rest will be fine.

9 comments