I find it pretty handy. I run any bash tools in a restricted sandbox, and so that it cannot hit the network (usually).
I don't want any credentials to be available to the agent, and my trust boundary for that is precisely the harness vs. the agent. Harness can touch secrets, agent can't (filesystem is restricted from it being able to read any secrets as well).
that's my one problem with the cli vs mcp debate. I prefer cli, because they're tools I'm familiar with, and they're composable. My problem with it is some cli tools need to use secrets to access things.
By making sure they only go to the harness, then I've got my problem solved.