AnalysisCybersecurityAugust 28, 2026

AI Agent Has Root: MCP servers run with full user permissions

A developer found that shell MCP servers in Claude run with the user's full permissions, giving AI agents access to SSH keys, AWS credentials, and the entire home directory with no audit trail. The post warns that unsandboxed MCP servers can act as the user without restrictions.

1 source

Daily brief

Get tomorrow's AI brief in your inbox

More stories today

Open the live feed