Tweet by StainlessAPI

February 20, 2026

MCP is approaching an inflection point, and the limiting factor is becoming obvious. Last week we held our first event in SF with @KeycardLabs, @Cloudflare, @temporalio, and @humanlayer_dev. We talked about what’s breaking in MCP right now, and what it will take to make agent-driven software robust. Some hard truths: - Many MCP servers work in demos but fail across real-world use cases. - “Giant agent skills” are becoming an anti-pattern with thousands of lines explaining things the model already knows, without clarity on the 5% it doesn’t. - Standard MCP approaches (one tool per endpoint or dynamic tools) scored ~50% correctness, but more advanced implementations reached ~70%. - The real kicker: when agents wrote code against production-grade SDKs, correctness jumped to 90–95%. But capability is only half the story. Control is the other half. An in-house Gmail MCP server was great for drafting emails… until it sent one unintentionally. The question isn’t just “can the agent do this?” but “what is it allowed to do?” OAuth scopes and coarse endpoint controls aren’t enough, and we’ll need fine-grained, programmable boundaries like: - Limit an agent to a single document - Cap refund amounts - Prevent broad, unintended actions If AI interfaces are going to replace dashboards, the underlying systems need to behave like an operating system kernel, not a shell script. Capability gets attention. Control earns trust. Trust is what scales.

Author
StainlessAPI
Date
February 20, 2026