The point that an MCP server is purely an interface, and an agent with shell access can just bypass it, is what most of the MCP hype skips. For local agents I've landed in the same place: a well-shaped CLI is easier to reason about, and the security boundary is imaginary either way. The unsolved part is the one you name, trusting third-party code running with my privileges. Have you found anything that actually constrains that, or is it still read-the-source-yourself?