AnalysisCybersecurityAugust 28, 2026

AI coding agents run with full user permissions via MCP

A developer found that running a shell MCP server in Claude gives the agent the same OS-level permissions as the user, including access to SSH keys, AWS credentials, and the entire home directory, with no audit trail or restrictions.

1 source

More stories today

Open the live feed