HN user

electric_muse

1,260 karma

NYC Building McpManager.ai

Posts14
Comments101
View on HN

But skills are not fundamentally different from *.instruction.md prompt in Copilot or AGENT.md and its variations.

One of the best patterns I’ve see is having an /ai-notes folder with files like ‘adding-integration-tests.md’ that contain specialized knowledge suitable for specific tasks. These “skills” can then be inserted/linked into prompts where I think they are relevant.

But these skills can’t be static. For best results, I observe what knowledge would make the AI better at the skill the next time. Sometimes I ask the AI to propose new learnings to add to the relevant skill files, and I adopt the sensical ones while managing length carefully.

Skills are a great concept for specialized knowledge, but they really aren’t a groundbreaking idea. It’s just context engineering.

Agreed. Only provide the servers and tools needed for that job.

It would be silly to provide every employee access to GitHub, regardless of whether they need it. It’s just distracting and unnecessary risk. Yet people are over-provisioning MCPs like you would install apps on a phone.

Principle of least access applies here just as it does anywhere else.

I think the most accurate part of your analogy is how fast the technology changes and renders yesterday’s product obsolete.

Just saw the Audi etron gt has amazing deals on used cars. Then I saw a new model coming out with better battery, more power, better range, and more features. Suddenly last year’s model is way less compelling.

Hey, did you read the article? The newsworthy point is that the EVs depreciate faster than gas counterparts.

But hey, that just means better used EV prices for the rest of us. You can get some high end gently used ones for a great price.

“ For Tesla owners in the U.S., their 2023 Model Ys are worth 42% less than what they paid two years ago, while a Ford F-150 truck bought the same year depreciated just 20%. Older EV models depreciate even faster than newer ones. ”

My use is more episodic than daily. But I love mine for many of the same reasons others have cited.

On a plane this is so useful. Flights go by much faster.

When traveling it’s so much less of a productivity drag to be able to pop this on and work with more real estate and focus.

The spatial videos and photos, whether taken with a real spatial device or upgraded later, are… so immersive. Seeing very old memories in 3d is emotional.

But I would pay so much to have a great gaming experience. Like a racing sim or something else realistic. The hardware is so impressive.

Frankly, I think this shines most as a consumption device for 3d content. There’s just not nearly enough yet.

Anyone ever experience Zoom meeting lag that reproducibly connects with receiving a Mac notification?

I've had this issue on my M1 and now my M4 mac for about a year now, and I can't figure it out. Uninstalling and reinstalling hasn't helped.

Literally, someone can reliably send me a slack notification in a meeting (even when DND is on) and cause my Zoom outbound video to get gummed up.

Edit: I ask because I wonder if it has to do with this.

AI just amplifies an existing organization. This paper generally confirms what I think most already know.

Executives are blaming the model quality, but that’s not the problem. It’s how well the AI understands what it is supposed to do and how connected it is to the information it needs.

If that organization understands their business processes well and has a team capable of adapting to new things, they will likely get AI to work for them and pull ahead.

But if that organization barely has their stuff together and isn’t all that good at adapting, then AI will fail to deliver meaningful results.

It’s basically just like amplified prompt engineering. Provide a vague prompt and you’ll get a low quality answer. But if you can properly communicate what you need, the AI generally will perform.

So TLDR it’s typically not the AI failing, it is the organizations failing to use AI.

Product Hunt is dead 10 months ago

I feel this.

Tried launching something in 2022. Night of the launch, my whole team pulls an all nighter.

Some launches suddenly pull ahead with 20 upvotes right out of the gate. We have a handful. I see the same LinkedIn messages this author cites, but I ignore them. Why cheat?

Once someone secure a top spot, all the traffic goes to those apps, and they stay ahead to matter what. Accumulative advantage.

1 hour later, we get hit with a cyberattack. We don’t have rate limiters on sending invites from validated users, and someone overwhelms that system. All the queues are flooded and grind to a halt.

We work furiously to resolve it. It takes hours to get everything flushed and healthy again.

We ended in 9th place or something.

Never again. I realized it’s just pay to play.

Agreed. I think most can agree that the protocol itself leaves a lot to be desired.

But the idea itself is compelling: documentation + invocation in a bi-directional protocol. And enough real players have thrown their weight behind making this thing work that it probably some day will.

I don't understand fully the "it's immature so it's worthy or ridicule" rationale so much. Don't most good things start out really rough around the edges? Why does MCP get so much disdain?

MCP feels like the 1903 Wright Flyer right now.

MCP is a novel technology that will probably transform our world, provides numerous advantages, comes with some risks, and requires skill to operate effectively.

Sure, none of the underlying technologies (JSON-RPC, etc.) are particularly novel. But the capability negotiation handshake built into the protocol is pretty darn powerful. It's a novel use of existing stuff.

I spent years in & around the domain of middleware and integrations. There's something really special about the promise of universal interoperability MCP offers.

Just like early-aviation, there are going to be tons of risks. But the upside is pretty compelling and worth the risks. You could sit around waiting for the kinks to get worked out or dive in and help figure out those kinks.

In fact, it seems I'm the first person to seriously draw attention to the protocol's lack of timeout coordination, which is a serious problem[0]. I'm just a random person in the ecosystem who got fed up with timeout issues and realized it's up to all of us to fix the problems as we see them. So there's still plenty of opportunity out there to jump in and contribute.

Kudos to this team for responsibly contributing what they found. These risks are inherent in any new technology.

[0] https://github.com/modelcontextprotocol/modelcontextprotocol...

MCP is like the "app store" for LLMs. LLMs can only do so much by themselves. They need connectivity to pull in context or take actions. Just like how your phone without apps is pretty limited in how useful it is.

Sure, teams could build their own connectors via function calling if they're running agents, but that only gets you so far. MCPs promise universal interoperability.

Some teams, like Block, are using MCP as a protocol but generally building their own servers.

But the vast majority are just sifting through the varying quality of published servers out there.

Those who are getting MCP to work are in the minority right now. Most just aren't doing it or aren't doing it well.

But there are plenty of companies racing into this space to make this work for enterprises / solve the problems you rightfully bring up.

As others have said here, the cat is out of the bag, and it is not going back in. MCP has enough buy-in from the community that it's likely to just get better vs. go away.

Source/Bias disclaimer: I pivoted my company to work on an MCP platform to smooth out those rough edges. We had been building integration technology for years. When a technology came along that promised "documentation + invocation" in-band over the protocol, I quickly saw that this could solve the pain of integration we had suffered for years. No more reading documentation and building integrations. The capability negotiation is built into the protocol.

Edit: a comma.

This is such a useful pattern.

I’ve ended up building similar things over and over again. For example, simplifying the worker-page connection in a browser or between chrome extension “background” scripts and content scripts.

There’s a reason many prefer “npm install” on some simple sdk that just wraps an API.

This also reminds me a lot of MCP, especially the bi-directional nature and capability focus.

Content is one thing. But it gets me really concerned about these kind of appeal processes when it comes to more critical things like your identity or proof of personhood.

It is not hard to imagine getting a black mark in some invisible proprietary profile that determines if you can access Uber Eats, LinkedIn, etc. and have no recourse to fix it or get another chance.

This whole “real phone number is your access code to every service” trend is really frustrating.

I had the same experience recently with: - Ticketmaster - Docusign - Vercel

Probably a handful more I forgot.

I believe the main reason is because it prevents fraud.

But I see a deeper motive that phone numbers are more friction to change and therefore our “real” numbers become hard-to-change identity codes that can easily be used to pull tons of info about you.

You give them that number and they immediately can look up your name, addresses, age, and tons of other mined info that was connected to you. Probably credit score, household income, etc.

Phone numbers have tons of “metadata” you provide without really knowing it. Like how the Exif data in a photo may reveal a lot about your location and device.

It’s still too early to see real benefits.

Wrapping business processes around these LLMs is the same kind of hard organizational problem plaguing most internal IT projects. People are still the bottleneck.

You also run into the issue of accuracy compounding. Running multi step flows with AI compounds the success rate and dramatically increases the chances of a full-job failure. E.g. even at 99% success rate for any single step, a 30-step process is only likely to succeed 75% of the time without errors. If you go down to 95% success for each, you only have a 75% likelihood of flawless execution at about 6 steps.

So it’s also about getting those per step success rates way up.

When the incentives are this large, it’s just too profitable to not “be evil.” We can decry this, but it’s just human nature.

I also think this is a sign of late stage capitalism where the opportunities to profit “ethically” are becoming much harder to find and exploit. That leads to more pressure to find gray areas that others’ ethical or moral convictions prevented them from exploiting.

I just installed graphene os on a brand new cash-bought pixel for the express purpose of not being left out of some important WhatsApp groups or missing out on some other experiences that require installing apps that I know won’t respect my privacy. I assume anything from Meta is hazardous at this point.

Well, nobody's forced it, but my company publishes content on TikTok that drives customers, and I want to be able to see it myself. You'd be surprised how many CISOs and security workers are on TikTok.

Edit: "experts" > "workers"

It's incredibly useful! I have one profile for the "social" apps I don't trust (TikTok, Reddit, etc.). They can commingle. And there's another profile that contains the apps that rely on Google Play Services (e.g. something relies on google maps). As far as I understand it, it's like a strong firewall between them such that they are pretty close to having multiple different phones.

I just bought a pixel from best buy to install gos, which was an ordeal.

At checkout they looked at me like I was up to no good when I said I didn’t want to give them my name, address, and phone number just to purchase the device. I didn’t set up a plan. They said it was for “restocking” or something.

Fortunately they accepted obviously fake info. These front line sales people just don’t care as long as they can say they followed the policy.

The user containers are very helpful. I have to have TikTok for work and I put it in a container all by itself with a vpn on kill switch. And for one app that needs google play services, I have it a container with that.

The duress passcode is super clever, too. You enter a different device passcode and it just wipes the device.

Yeah I thought a lot about this.

I was super hesitant at first but thought that this might be the most accepting place of any. For the most part, my comments were getting tons of upvotes and replies and so I thought “wow this is furthering the conversation. I should keep going!”

I wasn’t outsourcing the entire process after all. I moved from asking it to rephrase things I wrote (I’m sure plenty of people use grammarly and the like) to asking it to give me some drafts with a specific opinion and viewpoint, and then I would edit to my liking.

Anyway, this totally blew up and now I regret it. But it was an interesting ride because it really opened some interesting questions about the fact that these were some of the comments I made that the community upvoted the most, which to me is a sign of contributing value.

Yes, it is. Sort of.

I’m running an experiment.

A few days ago I flagged a piece someone else had written with ai. It has a specific cadence and some typical patterns. But many people seemed to buy it before I commented. I was surprised.

Today I pushed the boundary further and it clearly was that boundary.

Check my comment history.

I started out just saying “rephrase this so it sounds tighter” and moved recently towards just jotting rough notes and saying “make an HN comment out of this” and then editing.

I’ve been using gpt-5. I was going to see how Claude sonnet 4 performs at coming across as human-written / flagging some spidey senses.

(This was all by hand.)