HN user

egamirorrim

66 karma
Posts0
Comments104
View on HN
No posts found.

How can I have any confidence in the security of your product?

It's extremely hard to convince myself to use a product for the huge variety of often sensitive agent tasks when it's not open source. I understand the business reasons for that, but it's unusual in this space at the moment.

Instead: Can you post any independent security assessments perhaps? Fundamental things like SOC2?

I wish they'd release more stuff that didn't rely on me routing all my data through their cloud to work. Obviously the LLM is cloud based but I don't want any more lock-in than that. Plus not everyone has their repositories in GitHub.

It's more like you want Claude to interact with X, and you go to see if there's an MCP server for it.

Claude could use the API directly but most MCP now comes with OAuth so you can let it act as you, in case API keys are hard to come by or chargeable. Sometimes with a good skill or a preconfigured CLI tool skills can be just as good if not far more powerful than an MCP server.

But the trigger you'd look for to decide to use an MCP is 'i wish Claude could access X'. My top examples:

- pulling designs from figma to implement them - fetching ticket context for a job from JIRA - getting a stack trace to investigate from Sentry

Google Antigravity 8 months ago

I get so annoyed when Google launches things like this without Vertex support. Instant no-way from compliance and I'm left sitting on the sidelines.