Episode 239 - MCP: Hype, Security, and Real-World Use episode artwork

EPISODE · May 16, 2025 · 41 MIN

Episode 239 - MCP: Hype, Security, and Real-World Use

from Two Voice Devs · host Mark and Allen

Join us on Two Voice Devs as Allen Firstenberg talks with Rizel Scarlett, Tech Lead for Open Source Developer Relations at Block. Rizel shares her fascinating journey from psychology student to software engineer and now a leader in developer advocacy, highlighting her passion for teaching and creative problem-solving.The conversation dives deep into Block's innovative open source work, particularly their AI agent called Goose, which leverages the Model Context Protocol (MCP). Rizel explains what MCP is, seeing it as an SDK or API for AI agents, and discusses the excitement around its potential to democratize coding and other tools for developers and non-developers alike, sharing compelling use cases like automating tasks in Google Docs and interacting with Blender.However, the discussion doesn't shy away from the critical challenges facing MCP, especially concerning security. Rizel addresses concerns about trusting community-built MCP servers, potential vulnerabilities, and mitigation strategies like allow lists and building internal, vetted servers. They also explore the complexities of exposing large APIs, the demand for local AI for privacy, the current limitations of local models, and the user experience of installing and trusting MCP plugins.Rizel shares examples of promising MCP servers, including those focused on "long-term memory" and, notably, a speech/voice-controlled coding server, bringing the conversation back to the show's roots in voice development and accessibility, touching upon the concept of temporary disability.The episode concludes by reflecting on whether MCP is currently a "small, beginner solution" being hyped as a "massive, full-featured" one, the need for more honest conversations about its limitations, and the ongoing efforts within the community and companies like Block to improve the protocol, including discussions around official registries and easier installation methods like deep links.Tune in for a candid look at the exciting, yet challenging, landscape of AI agents, MCP, and open source development.More Info:* Goose - https://github.com/block/goose* Pieces for Developers - https://pieces.app/features/mcp* Speech MCP - https://glama.ai/mcp/servers/@Kvadratni/speech-mcp[00:00:48] Meet Rizel Scarlett & Her Career Journey (Psychology to Dev Advocacy)[00:03:54] Introducing Block & Its Mission (Square, Cash App, etc.)[00:04:58] Block's Open Source Division and the Goose AI Agent[00:05:48] Diving into the Model Context Protocol (MCP)[00:07:56] What is MCP? (SDK for Agents) & Exciting Use Cases (Democratization, non-developers)[00:10:36] Major Security Concerns with MCP (Trust, vulnerabilities, typo squatting)[00:11:48] Mitigation Strategies & Authentication (Allow Lists, Internal Servers, Vetting)[00:17:59] The Current State of MCP: An Infancy Protocol[00:20:09] Complexity & Context Window Challenges with MCP Servers[00:23:14] User Demand for Local AI & Data Privacy[00:25:31] User Experience of MCP Plugin Installation & Trust[00:28:42] Examples of Useful MCP Servers (Pieces, Computer Controller, Speech)[00:31:18] The Power of Voice-Controlled Coding (Accessibility, temporary disability)[00:33:59] MCP: Hype vs. Reality & The Need for Honest Conversations[00:36:00] Efforts to Improve MCP (Committees, Registries, Deep Links)#developer #programming #tech #opensource #block #ai #aigent #llm #mcp #modelcontextprotocol #devrel #developeradvocacy #security #cybersecurity #privacy #localai #remoteai #accessibility #voicecoding #riselscarlett #gooseai

Join us on Two Voice Devs as Allen Firstenberg talks with Rizel Scarlett, Tech Lead for Open Source Developer Relations at Block. Rizel shares her fascinating journey from psychology student to software engineer and now a leader in developer advocacy, highlighting her passion for teaching and creative problem-solving.The conversation dives deep into Block's innovative open source work, particularly their AI agent called Goose, which leverages the Model Context Protocol (MCP). Rizel explains what MCP is, seeing it as an SDK or API for AI agents, and discusses the excitement around its potential to democratize coding and other tools for developers and non-developers alike, sharing compelling use cases like automating tasks in Google Docs and interacting with Blender.However, the discussion doesn't shy away from the critical challenges facing MCP, especially concerning security. Rizel addresses concerns about trusting community-built MCP servers, potential vulnerabilities, and mitigation strategies like allow lists and building internal, vetted servers. They also explore the complexities of exposing large APIs, the demand for local AI for privacy, the current limitations of local models, and the user experience of installing and trusting MCP plugins.Rizel shares examples of promising MCP servers, including those focused on "long-term memory" and, notably, a speech/voice-controlled coding server, bringing the conversation back to the show's roots in voice development and accessibility, touching upon the concept of temporary disability.The episode concludes by reflecting on whether MCP is currently a "small, beginner solution" being hyped as a "massive, full-featured" one, the need for more honest conversations about its limitations, and the ongoing efforts within the community and companies like Block to improve the protocol, including discussions around official registries and easier installation methods like deep links.Tune in for a candid look at the exciting, yet challenging, landscape of AI agents, MCP, and open source development.More Info:* Goose - https://github.com/block/goose* Pieces for Developers - https://pieces.app/features/mcp* Speech MCP - https://glama.ai/mcp/servers/@Kvadratni/speech-mcp[00:00:48] Meet Rizel Scarlett & Her Career Journey (Psychology to Dev Advocacy)[00:03:54] Introducing Block & Its Mission (Square, Cash App, etc.)[00:04:58] Block's Open Source Division and the Goose AI Agent[00:05:48] Diving into the Model Context Protocol (MCP)[00:07:56] What is MCP? (SDK for Agents) & Exciting Use Cases (Democratization, non-developers)[00:10:36] Major Security Concerns with MCP (Trust, vulnerabilities, typo squatting)[00:11:48] Mitigation Strategies & Authentication (Allow Lists, Internal Servers, Vetting)[00:17:59] The Current State of MCP: An Infancy Protocol[00:20:09] Complexity & Context Window Challenges with MCP Servers[00:23:14] User Demand for Local AI & Data Privacy[00:25:31] User Experience of MCP Plugin Installation & Trust[00:28:42] Examples of Useful MCP Servers (Pieces, Computer Controller, Speech)[00:31:18] The Power of Voice-Controlled Coding (Accessibility, temporary disability)[00:33:59] MCP: Hype vs. Reality & The Need for Honest Conversations[00:36:00] Efforts to Improve MCP (Committees, Registries, Deep Links)#developer #programming #tech #opensource #block #ai #aigent #llm #mcp #modelcontextprotocol #devrel #developeradvocacy #security #cybersecurity #privacy #localai #remoteai #accessibility #voicecoding #riselscarlett #gooseai

NOW PLAYING

Episode 239 - MCP: Hype, Security, and Real-World Use

0:00 41:28

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

The Small Business Startup School – Business Notes | Financial Literacy | Retail Psychology – For Professionals & Entrepreneurs The Small Business Startup School Inc. Starting or buying a small business? While personal circumstances may vary, business patterns remain timeless. On The Small Business Startup School, we explore strategies, insights, and practical solutions to help entrepreneurs confidently navigate their journey.Hosted by Ola Williams—a retail entrepreneur, fintech founder, and financial coach with over two decades of experience—this podcast marries financial awareness and retail psychology with optimism to deliver actionable takeaways.Join us to learn, grow, and connect as we uncover the keys to business success.Let’s continue to learn together and be encouraged to keep on connecting! 2 Old Ladies Walking Rozee 2 Old Ladies Walking features the journeys, insights, and light conversation between Liz and Rosie, two women of a certain age who live in the Hudson Valley of New York. From pelvic floor challenges and life with young adult children to food, bird calls, fear of “mad lamb” disease, and myriad topics in between, we cover it all while walking on the scenic trails of the northeast, or wherever our travels take us. Join us and have a listen! Radio Maria Kenya Radio Maria Kenya A Christian voice in Kenya and in the World Two Recruiters: Zero Filter Two Recruiters At Two Recruiters: Zero Filter, we're on a mission to demystify the hiring process, share insider tips, and empower you to maneuver through the professional world with confidence. With more than 30 years of combined experience navigating the intricate web of job markets, talent acquisition, and career development, we're here to spill the tea on everything career related. But wait, there’s more! We will dive into many life topics that are interesting to us as well.  Get ready for a rollercoaster of insights, stories, and no-holds-barred advice!Join us for conversations that matter – where work, life, and authenticity collide in the most unexpected and rewarding ways.

Frequently Asked Questions

How long is this episode of Two Voice Devs?

This episode is 41 minutes long.

When was this Two Voice Devs episode published?

This episode was published on May 16, 2025.

What is this episode about?

Join us on Two Voice Devs as Allen Firstenberg talks with Rizel Scarlett, Tech Lead for Open Source Developer Relations at Block. Rizel shares her fascinating journey from psychology student to software engineer and now a leader in developer...

Can I download this Two Voice Devs episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!