> The MCP specification recommends human oversight for this type of tool – there should always be a human in the loop with the ability to deny tool invocations, meaning users would review these queries before execution.
They are not intended to run unsupervised with privileges. There is no exploit vector since the human will not allow malicious queries to run. Sounds reasonable, assuming they never sold it as anything else.
baobun•4h ago
> The MCP specification recommends human oversight for this type of tool – there should always be a human in the loop with the ability to deny tool invocations, meaning users would review these queries before execution.
They are not intended to run unsupervised with privileges. There is no exploit vector since the human will not allow malicious queries to run. Sounds reasonable, assuming they never sold it as anything else.