Even on your own machine with CLI tools , you really think it’s a great idea to let the LLM use the CLI as if it were you, with all permissions you have without any way to differentiate between actions you have manually taken and those that the LLM did? I hope the answer is no and you sandbox the agent with its own permissions and user, but if you do that perhaps MCP does not look so bad anymore!?

Why would you let the llm use the CLI as you?

Because that is convenient and everyone does it??

Just give it a different user with different permissions if yoirewon Linux. This is half century old tech.