I noticed the security aspect to be one of the main selling points in corporations for going MCP (and one aspect that is underrepresented here).
However, maybe I'm missing something but how is defining access rights in an application layer the agent has access to more secure than defining the access rights at the target application itself?
Sure, hiding the filesystem via encapsulation tricks is one way to go. But what is the real-world usage-style of this vs. all MCP usages? I'd wager 1-10% are spending this extra effort, while 90% of users basically run shims so that they can expose APIs to their LLMs, for which they have no/bad access rights management.