无状态 MCP 重新引起了我的兴趣

Stateless MCP has recaptured my interest

西蒙·威利森 Simon Willison · · 2026-07-31 · Simon Willison's Weblog ↗

打开互动全文版(逐段中英对照 + 图/公式 + 论文问答)→

摘要 · Abstract

赞助方:AWS——利用覆盖技术栈每一层的 ISV 资源,从 SaaS 迈向 Agentic SaaS。探索面向 ISV 的 AI 如何将愿景转化为成果。

Sponsored by: AWS — Move from SaaS to Agentic SaaS with resources for ISVs at every layer of the stack. Explore how AI for ISVs turns vision into results

核心贡献 · Key contributions

局限 · Limitations

论文章节 · Sections(共 9)

全文 · Full text(逐段中英对照)

Simon Willison 的博客 Simon Willison’s Weblog(https://simonwillison.net/)

赞助商:AWS —— 借助面向 ISV 的全栈资源,从 SaaS 迈向智能体式 SaaS。探索 AI 如何为 ISV 将愿景转化为成果。

Sponsored by: AWS — Move from SaaS to Agentic SaaS with resources for ISVs at every layer of the stack. Explore how AI for ISVs turns vision into results

无状态 MCP 重新引起我的兴趣(并启发了 mcp-explorer 和 datasette-mcp) Stateless MCP has recaptured my interest (and inspired mcp-explorer and datasette-mcp)

星期二是无状态 MCP 日——也就是 MCP 2.0 的发布,或者用更正式但更不容易记住的名字来说,是 2026-07-28 的模型上下文协议规范。这是自 MCP 首次发布以来最重大的变化,也重新点燃了我个人对该协议的兴趣。

Tuesday was Stateless MCP day—the rollout of MCP 2.0, or the 2026-07-28 Model Context Protocol specification to use the more formal but less memorable name. This is the most significant change to the MCP spec since it first launched, and has also served to reignite my personal interest in the protocol.

背景说明:MCP 是模型上下文协议(Model Context Protocol),它描述了一种将新工具暴露给基于 LLM 的智能体框架的标准方式。该协议由 Anthropic 于 2024 年 11 月推出,在 2025 年的大部分时间里引发了巨大的关注热潮,但后来逐渐被 Skills(Anthropic 的另一项发明)所掩盖,因为人们发现,一个能够访问终端和 curl 的智能体工具框架,可以用更灵活的方式完成 MCP 能做的大部分事情。我在 2025 年回顾中写过这一点。

For background: MCP is the Model Context Protocol, which describes a standard way to expose new tools to LLM-powered agent frameworks. It was introduced by Anthropic back in November 2024, had a _huge_ spike of interest through much of 2025, and then became somewhat eclipsed by Skills (another Anthropic invention) when it became apparent that an agent harness with access to a terminal and curl could do most of what MCP did in a more flexible way. I wrote about that in my review of 2025.

现在我重新回到了 MCP 这边。给智能体一个能够访问互联网的 shell 环境充满了风险,而且需要一个足够强大的模型,能够有效地驱动这样的环境。MCP 工具更容易审计和控制,而且足够简单,即使是在笔记本电脑上运行的较小模型,也能相当好地驱动它们。

I’m coming back around to MCP now. Giving an agent a shell environment with the ability to access the internet is fraught with risk, and requires a strong model that is capable of effectively driving such an environment. MCP tools are easier to audit and control, and simple enough that smaller models that run on a laptop can still drive them reasonably well.

新的无状态 MCP 规范还大大降低了为协议实现客户端和服务器的复杂度。本周我就构建了三个这样的实现!

The new stateless MCP specification also greatly decreases the complexity of implementing both clients and servers for the protocol. I built three of those this week!

无状态 MCP 的便利之处 What’s easier with stateless MCP

关于有状态与无状态 MCP 之间差异的最佳演示,来自 5 月 21 日那篇介绍新规范 RC 的博客文章。其中包含一个清晰的“前后对比”示例。

The best demonstration of the difference between stateful and stateless MCP is in this May 21st blog post that introduced the RC for the new specification. It included a clear before-and-after example.

旧版的有状态 MCP(我将其称为“传统 MCP”)需要两个 HTTP 请求——第一个用于初始化会话并获得 Mcp-Session-Id,第二个用于实际调用工具:

The older stateful MCP (I’m going to call it “legacy MCP”) required two HTTP requests—the first to initialize a session and obtain a Mcp-Session-Id, and the second to actually call the tool:

新的无状态方式只需单个 HTTP 请求,如下所示:

The new stateless way uses a single HTTP request which looks like this:

无论从客户端还是服务端的实现角度来看,这都简洁得多。它也更适合构建可扩展的 Web 应用,因为现在你无需维护服务端状态来跟踪那些会话 ID,也无需担心将同一会话路由到同一台后端机器。

This is so much cleaner from both a client- and server-side implementation perspective. It’s also a better fit for building scalable web applications, since now you don’t need to maintain server-side state to keep track of those session IDs, or worry about routing the same session to the same backend machine.

mcp-explorer:MCP 服务器交互式探测工具 mcp-explorer

我找不到一个能交互式探测 MCP 服务器的出色 CLI 工具,于是让 Codex 帮我构建了一个。

I couldn’t find a great CLI tool for interactively probing an MCP server, so I had Codex help build my own.

mcp-explorer 就是结果。它是一个无状态的 Python CLI 工具,因此你甚至无需安装即可试用——通过 uvx 即可运行,如下所示:

mcp-explorer is the result. It’s a stateless Python CLI tool, so you don’t even need to install it to try it out—it works with uvx like this:

uvx mcp-explorer list https://agentic-mermaid.dev/mcp

uvx mcp-explorer list https://agentic-mermaid.dev/mcp

该命令查询 Ade Oshineye 的 agentic-mermaid.dev 演示 MCP。上述命令返回以下工具列表:

This queries Ade Oshineye’s agentic-mermaid.dev demo MCP. The above command returns the following list of tools:

execute(code: string, timeoutMs?: integer) - 执行 Mermaid SDK 代码

execute(code: string, timeoutMs?: integer) - Execute Mermaid SDK code

在隔离的沙箱中运行 JavaScript;返回一个值。

Run JavaScript in an isolated sandbox; return a value.

describe_sdk(family: string, detail?: string) - 描述 Mermaid SDK 操作

describe_sdk(family: string, detail?: string) - Describe Mermaid SDK operations

返回一个图表系列对应的版本匹配的变更操作。

Return version-matched mutation operations for one diagram family.

render_svg(source: string, options?: object) - 将 Mermaid 渲染为 SVG

render_svg(source: string, options?: object) - Render Mermaid as SVG

将 Mermaid 源字符串渲染为可主题化的 SVG。返回 { ok, svg }。

Render a Mermaid source string to themeable SVG. Returns { ok, svg }.

render_ascii(source: string, useAscii?: boolean, targetWidth?: integer, options?: object) - 将 Mermaid 渲染为文本

render_ascii(source: string, useAscii?: boolean, targetWidth?: integer, options?: object) - Render Mermaid as text

将 Mermaid 源字符串渲染为文本。返回 { ok, text }。

Render a Mermaid source string to text. Returns { ok, text }.

render_png(source: string, scale?: number, background?: string, fitTo?: object, options?: object) - 将 Mermaid 渲染为 PNG

render_png(source: string, scale?: number, background?: string, fitTo?: object, options?: object) - Render Mermaid as PNG

将 Mermaid 源字符串栅格化为 PNG。返回 { ok, png_base64 }。

Rasterize a Mermaid source string to PNG. Returns { ok, png_base64 }.

这将输出大量信息,包括输入和输出的 JSON 模式。

This outputs a whole bunch of information, including the JSON schema of the inputs and outputs.

要调用该工具并向其传递参数:

To call that tool and pass arguments to it:

```json {"ok":true,"svg":"<svg xmlns=\"http://www.w3.org/2000/svg\" width=...} ```

```json {"ok":true,"svg":"<svg xmlns=\"http://www.w3.org/2000/svg\" width=...} ```

要获取原始 SVG,请尝试在该命令后加上 `| jq .svg -r`。我得到了这张图片:

To get just the raw SVG, try adding `| jq .svg -r` to that command. I got back this image:

README 中还有几个命令,但你已经了解了大致思路。我认为构建这样的 CLI 工具是熟悉规范的一种非常高效的方式,即使大部分实际代码是由智能体编写的。

There are a few more commands in the README, but you get the general idea. I find building CLI tools like this to be a really productive way to get familiar with a specification, even if an agent writes most of the actual code.

datasette-mcp datasette-mcp

第二个项目是 datasette-mcp,这是一个 Datasette 插件,可为任何 Datasette 实例添加 /-/mcp 端点。

The second project is datasette-mcp, a Datasette plugin which adds a /-/mcp endpoint to any Datasette instance.

这大概是我第四次尝试构建这个插件,但多亏了新的无状态 MCP 规范,我终于有了一个可以满意发布的版本。

This is probably the fourth time I’ve tried building this plugin, but thanks to the new stateless MCP specification I finally have a version that feels good to release.

它只提供三个工具:list_databases()、get_database_schema(database_name) 和 execute_sql(database_name, sql)。它们的作用正如你所预期——不过 execute_sql() 目前是只读的。

It provides just three tools: list_databases(), get_database_schema(database_name), and execute_sql(database_name, sql). They do exactly what you would expect them to do—though execute_sql() is read-only for the moment.

将它们接入智能体,或像 ChatGPT 或 Claude 这样的聊天工具,它们就能获得对你的托管 Datasette 实例运行 SQL 查询的能力。

Wire these into an agent, or a chat tool like ChatGPT or Claude, and they’ll gain the ability to run SQL queries against your hosted Datasette instance.

目前,我正将它运行在我的博客的 Datasette 镜像上,地址是 datasette.simonwillison.net/-/mcp。我花了一些功夫才弄清楚如何将其接入 ChatGPT 和 Claude,但最终还是搞定了。这里有一个新的 TIL,详细展示了具体做法。

So far I’m running it on the Datasette mirror of my blog, at datasette.simonwillison.net/-/mcp. It took a bit of fiddling to figure out how to attach that to ChatGPT and Claude, but I got there in the end. Here’s a new TIL showing exactly how to do that.

以下是一个共享的 Claude 会话,我问了它:

Here's a shared Claude session where I asked it:

它运行了 7 条独立的 SQL 查询来找出答案。

It ran 7 separate SQL queries to figure out the answer.

llm-mcp-client llm-mcp-client

我的 LLM 工具早就该有一个官方的 MCP 集成了。新的 alpha 版 llm-mcp-client 插件正是我为实现这一目标所做的尝试:

My LLM tool is long overdue for an official MCP integration. The new alpha llm-mcp-client plugin is my attempt at exactly that:

llm -T 'MCP("https://datasette.simonwillison.net/-/mcp")' 'count the notes'

llm -T 'MCP("https://datasette.simonwillison.net/-/mcp")' 'count the notes'

以下是输出(包括推理轨迹,我使用的是 LLM 0.32rc2):

Here’s the output (including reasoning trace, I’m using LLM 0.32rc2):

以及该提示词的 llm logs 输出。

And the output of llm logs for that prompt.

一旦这个功能完全成熟,我正在考虑将其直接纳入 LLM 核心。我也很期待在 Datasette Agent 和 llm-coding-agent 中尝试 MCP。

Once this is fully baked, I’m considering bringing it directly into LLM core. I’m excited to experiment with MCP in Datasette Agent and llm-coding-agent as well.

MCP 是构建智能体的一种更安全的方式 MCP is a safer way to build with agents

在 MCP 首次发布几个月后,我写了《Model Context Protocol 存在提示注入安全问题》一文,其中我指出,让最终用户自行混搭工具的模式,将避免数据外泄攻击的责任推给了用户自己。那时我还没有提出“致命三重奏”这个概念,但毫无疑问那就是我心中所想。

A few months after MCP was first released, I wrote Model Context Protocol has prompt injection security problems, where I noted that the pattern of having end users mix and match tools pushed responsibility for avoiding data exfiltration attacks out to the users themselves. I hadn’t coined the Lethal Trifecta yet, but that was absolutely what I had in mind.

然后,拥有任意 shell 和 curl 访问权限的通用智能体出现了,这让安全防护变得更加困难!

Then general agents with arbitrary shell and curl access came along, and that’s so much harder to keep secure!

关于 MCP,我逐渐欣赏的一点是,相比于在开放网络环境中任意执行命令——这是当今大多数通用及编程智能体工具的默认方式——用它来推理智能体能力以及可能出错的地方要容易得多。

Something I’ve come to appreciate about MCP is that it’s much easier to reason about agent capabilities and what might go wrong than with arbitrary command execution in an open network environment—the default for most of today’s general and coding agent tools.

当我基于大语言模型构建敏感应用时,我计划更多地依赖 MCP。

I plan to lean into MCP a whole lot more when I’m building sensitive applications on top of LLMs.

发布于 2026 年 7 月 31 日 23:13 · 在 Mastodon、Bluesky、Twitter 上关注我,或订阅我的通讯

Posted 31st July 2026 at 11:13 pm · Follow me on Mastodon, Bluesky, Twitter or subscribe to my newsletter

更多近期文章 More recent articles

OpenAI 对 Hugging Face 的意外网络攻击是已成现实的科幻小说 - 2026 年 7 月 22 日

OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened - 22nd July 2026

与 Claude Code 团队的 Cat 和 Thariq 的炉边谈话 - 2026 年 7 月 21 日

A Fireside Chat with Cat and Thariq from the Claude Code team - 21st July 2026

这就是“Stateless MCP”,它重新引起了我的兴趣(并启发了 mcp-explorer 和 datasette-mcp),作者:Simon Willison,发布于 2026 年 7 月 31 日。

This is “Stateless MCP”, which has recaptured my interest (and inspired mcp-explorer and datasette-mcp) by Simon Willison, posted on 31st July 2026.

projects 549、ai 2,157、datasette 1,530、mermaid 5、generative-ai 1,909、llms 1,876、llm 616、anthropic 320、model-context-protocol 31

projects 549, ai 2,157, datasette 1,530, mermaid 5, generative-ai 1,909, llms 1,876, llm 616, anthropic 320, model-context-protocol 31

上一篇:OpenAI 对 Hugging Face 的意外网络攻击是已成现实的科幻小说

Previous: OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened

月度简报 Monthly briefing

每月赞助我 10 美元,即可收到一封精选邮件摘要,汇总本月最重要的大语言模型(LLM)进展。

Sponsor me for $10/month and get a curated email digest of the month's most important LLM developments.

互动版:图/公式 + 针对本篇提问 →