Tech & AI News
Hacker News

AI Agent Has Root

The author discovered that an MCP server runs with the same user ID and permissions as the host user, granting it unrestricted access to the entire home directory, SSH keys, cloud credentials, GPG keyring, and any writable files. Consequently, an unsandboxed MCP server can read, modify, delete, exfiltrate data, push code, install packages, and make network requests without sudo or alerts, making prompt injection a critical security risk.