HC
I think that's the key takeaway: MCP isn't the security model, it's just the protocol. If the same business rules, authorization, and validation aren't enforced behind the MCP layer, you've only created a new entry point into your system. Keeping tools narrow and exposing business capabilities instead of internals is probably the biggest design win for production AI apps.