The universal-adapter analogy is useful as long as standardized tool discovery is not mistaken for standardized authorization. An MCP server still needs per-user credential mapping, least-privilege scopes, idempotency, and an audit trail around the underlying APIs. In the delivery-address example, I would expose read and write operations separately and re-check the shipped state transactionally at execution time, not only when the agent plans the action.