Pi used to advertise that it did not support the Model Context Protocol (MCP), a common way for AI agents to connect to outside tools. Earendil Engineering now explains the reversal: MCP improved, but more importantly, supporting it forced Pi to build machinery that is useful beyond MCP.

The post’s diagnosis is that MCP still struggles with composition — getting several tools to work together without dumping every tool and every intermediate result into the model’s limited working context.

Pi’s answer is to treat MCP more like a catalog of structured interfaces:

  • Discover tools from their documentation only when they are needed.
  • Have tools return structured data rather than prose meant for the model to reread.
  • Defer loading tools instead of placing the full list into every prompt.
  • Let the model coordinate parallel and dependent calls in a JavaScript sandbox called Codemode.

Codemode runs beside the agent’s control loop rather than as a shell command on the host. That gives the model a place to combine MCP calls, keep useful state in the session, and filter results before they consume context. The essay’s real contribution is not “MCP won”; it is a concrete account of how a small coding-agent harness can adopt a broad standard without accepting its clumsiest usage patterns.

The 89-comment thread on Hacker News adds practical alternatives and exposes the security question the article leaves open.

What the thread adds

  • statenjason — describes a shell-first alternative: “It exposes MCPs as shell commands. Agents compose using standard shell primitives. Tool returns json? Pipe into jq.” The same interface is available to the developer, which they call “Super valuable when debugging.”
  • hobofan — states the case against making the shell the universal answer: “running the harness server-side, as is the case for chat interfaces, you don’t really want to expose OS shell access as that opens up a huge security attack surface.”
  • alin23 — reports using MCP in macOS apps so a local model can configure existing automation safely, arguing that reproducing those mature integrations from scratch would require “a much more capable coding model.”
  • sunaookami — provides real dissent from the trend toward elaborate agent machinery: “I disabled all sub-agents stuff, disabled nearly all tools but Bash, Edit, Write and WebSearch,” because sub-agents lacked context and weaker models summarized poorly.

The unanswered sandbox question

coder-pm asks what Pi’s JavaScript sandbox actually is — “container, separate process, same Node process?” — and whether it can access MCP tokens or harness credentials. The article explains the trust boundary in general terms but does not answer those deployment details.

HN handles are pseudonymous and HN publishes no per-comment scores. The ordering is HN’s own ranking, so this is a slice of the thread and not a consensus.