| ▲ | lowcache 2 days ago | ||||||||||||||||||||||
Author of the post, and dev of mcp-box here. Wrote this after realizing every MCP server on my machine had the same access to ~/.ssh that I do, and nothing in the installation messages posting to stdout mentions it. I think prompt injection is the vector and the permissions model is the red carpet giving a warm welcome. Interested in where that's wrong. | |||||||||||||||||||||||
| ▲ | themgt 2 days ago | parent | next [-] | ||||||||||||||||||||||
Wrote this after realizing every MCP server on my machine had the same access to ~/.ssh that I do I have some bad news ... I hope you're sitting down. | |||||||||||||||||||||||
| ▲ | chollida1 2 days ago | parent | prev [-] | ||||||||||||||||||||||
Isn't a best practice to run llm's and agents under their own user that gives them only access to what they require? How would an llm suddenly get access to your ~/.ssh folder if you didn't expressly give it access? | |||||||||||||||||||||||
| |||||||||||||||||||||||