AI Agent Has Root: MCP servers run with full user permissions

A developer found that shell MCP servers in Claude run with the user's full permissions, giving AI agents access to SSH keys, AWS credentials, and the entire home directory with no audit trail. The post warns that any malicious code in an MCP server could act as the user.
1 source
Cybersecurity by email
Get an email when there's news on Cybersecurity
No news that day, no email.
More stories today
- Empirik launches with $21M to predict IT outages
- Musk: AI to boost global economy 20-30%
- Atos upskills 400 engineers in agentic AI with AWS
- Top AI open source projects shut off PRs, use own agents
- AWS details securing Amazon Quick from POC to production