logo
episode-header-image
May 16
41m 28s

Episode 239 - MCP: Hype, Security, and R...

Mark and Allen
About this episode

Join us on Two Voice Devs as Allen Firstenberg talks with Rizel Scarlett, Tech Lead for Open Source Developer Relations at Block. Rizel shares her fascinating journey from psychology student to software engineer and now a leader in developer advocacy, highlighting her passion for teaching and creative problem-solving.

The conversation dives deep into Block's innovative open source work, particularly their AI agent called Goose, which leverages the Model Context Protocol (MCP). Rizel explains what MCP is, seeing it as an SDK or API for AI agents, and discusses the excitement around its potential to democratize coding and other tools for developers and non-developers alike, sharing compelling use cases like automating tasks in Google Docs and interacting with Blender.

However, the discussion doesn't shy away from the critical challenges facing MCP, especially concerning security. Rizel addresses concerns about trusting community-built MCP servers, potential vulnerabilities, and mitigation strategies like allow lists and building internal, vetted servers. They also explore the complexities of exposing large APIs, the demand for local AI for privacy, the current limitations of local models, and the user experience of installing and trusting MCP plugins.

Rizel shares examples of promising MCP servers, including those focused on "long-term memory" and, notably, a speech/voice-controlled coding server, bringing the conversation back to the show's roots in voice development and accessibility, touching upon the concept of temporary disability.

The episode concludes by reflecting on whether MCP is currently a "small, beginner solution" being hyped as a "massive, full-featured" one, the need for more honest conversations about its limitations, and the ongoing efforts within the community and companies like Block to improve the protocol, including discussions around official registries and easier installation methods like deep links.

Tune in for a candid look at the exciting, yet challenging, landscape of AI agents, MCP, and open source development.


More Info:

* Goose - https://github.com/block/goose

* Pieces for Developers - https://pieces.app/features/mcp

* Speech MCP - https://glama.ai/mcp/servers/@Kvadratni/speech-mcp


[00:00:48] Meet Rizel Scarlett & Her Career Journey (Psychology to Dev Advocacy)

[00:03:54] Introducing Block & Its Mission (Square, Cash App, etc.)

[00:04:58] Block's Open Source Division and the Goose AI Agent

[00:05:48] Diving into the Model Context Protocol (MCP)

[00:07:56] What is MCP? (SDK for Agents) & Exciting Use Cases (Democratization, non-developers)

[00:10:36] Major Security Concerns with MCP (Trust, vulnerabilities, typo squatting)

[00:11:48] Mitigation Strategies & Authentication (Allow Lists, Internal Servers, Vetting)

[00:17:59] The Current State of MCP: An Infancy Protocol

[00:20:09] Complexity & Context Window Challenges with MCP Servers

[00:23:14] User Demand for Local AI & Data Privacy

[00:25:31] User Experience of MCP Plugin Installation & Trust

[00:28:42] Examples of Useful MCP Servers (Pieces, Computer Controller, Speech)

[00:31:18] The Power of Voice-Controlled Coding (Accessibility, temporary disability)

[00:33:59] MCP: Hype vs. Reality & The Need for Honest Conversations

[00:36:00] Efforts to Improve MCP (Committees, Registries, Deep Links)



#developer #programming #tech #opensource #block #ai #aigent #llm #mcp #modelcontextprotocol #devrel #developeradvocacy #security #cybersecurity #privacy #localai #remoteai #accessibility #voicecoding #riselscarlett #gooseai

Up next
Jul 31
Episode 250 - Five Years Up, Up, and Away in Voice & AI
Join Mark and Allen for a very special 250th episode as they celebrate five years of Two Voice Devs! You won't want to miss the unique, AI-animated opening that takes them to new heights, or the special closing that brings it all home, both created with the help of Veo 3. In betw ... Show More
36m 14s
Jul 24
Episode 249 - Cracking Copilot and the Mysteries of Microsoft 365
In this episode, guest host Andrew Connell, a Microsoft MVP of 21 years, joins Allen to unravel the complexities of Microsoft's AI strategy, particularly within the enterprise. They explore the world of Microsoft 365 Copilot, distinguishing it from the broader AI landscape and co ... Show More
52m 7s
Jul 17
Episode 248 - AI Showdown: Gemini CLI vs. Claude Code CLI
Join Allen Firstenberg and guest host Isaac Johnson, a Google Developer Expert with a deep background in DevOps and SRE, as they dive into the world of command-line AI assistants. In this episode, they compare and contrast two powerful tools: Anthropic's Claude Code CLI and Googl ... Show More
41m 31s
Recommended Episodes
Nov 2024
Making Sense of Agentic AI | ThoughtWorks Birgitta Boeckeler
There’s AI agents. There’s AI tooling. Do either drive business impact or are they just more things your dev team is supposed to stay on top of? Birgitta Boeckeler, Global Lead for AI Assisted Software Delivery at ThoughtWorks, joins the show to discuss the practical applications ... Show More
47m 40s
Sep 2023
Meta’s Quest 3, AI chatbots and Ray-Ban smart glasses
This week, it’s Meta’s turn to highlight AI during its device event. In this episode, Devindra and Cherlynn dive into all of the news from Meta’s Connect 2023 event, where it unveiled Meta AI and accompanying celebrity-powered chatbots. Oh yah, and it introduced the Meta Quest 3 ... Show More
1h 6m
Sep 2024
Study Reveals Vulnerabilities in Alexa, Siri, and Google Assistant to Malicious Commands
In this episode, we explore a recent study that uncovers how popular voice assistants like Alexa, Siri, and Google Assistant are susceptible to malicious commands. We discuss the potential risks and what users can do to protect their devices. Get on the AI Box Waitlist: ⁠⁠⁠https: ... Show More
6m 17s
Nov 2024
SN 1001: Artificial General Intelligence (AGI) - Gmail Temp Addresses, Russia's Internet Off Switch
How Microsoft lured the US Government into a far deeper and expensive dependency upon its cybersecurity solutions. Gmail to offer native throwaway email aliases like Apple and Mozilla. Russia to ban several additional hosting companies and give its big Internet disconnect switch ... Show More
2h 26m
Sep 2024
AI is more than GenAI
GenAI is often what people think of when someone mentions AI. However, AI is much more. In this episode, Daniel breaks down a history of developments in data science, machine learning, AI, and GenAI in this episode to give listeners a better mental model. Don’t miss this one if y ... Show More
40m 3s
Jul 2019
AWS’ new text-to-speech engine sounds like a newscaster
Thanks to modern machine learning techniques, text-to-speech engines have made massive strides over the last few years. It used to be incredibly easy to know that it was a computer that was reading a text and not a human being. But that’s changing quickly. Amazon’s AWS cloud comp ... Show More
2m 48s
Jan 2021
How Salesforce will make Einstein smarter in 2021
Salesforce launched Einstein, its artificial intelligence tool, in 2016. It was memorable because of the marketing materials, featuring a cute cartoon of the world's most misquoted-scientist. It was also memorable because of the unique capabilities Einsten brought to the table. T ... Show More
27m 46s
May 2021
397: Customer Feedback vs. Team Intuition
This week, we talk about the tension between building what customers explicitly ask for versus building towards a team’s internal vision. In The Sidebar, we talk about the lack of public software critique: Why isn’t there an MKBHD equivalent for software design?Golden Ratio Suppo ... Show More
23m 29s