The MCP approve dialog is not a security boundary
This story is from 2026-09-17. It is preserved in the archive; the latest stories are on the live feed.
If you wire MCP into Cursor or Claude Code, the approve dialog is not a security boundary. It shows the tool description your client can render. It does not show Unicode TAG-block payloads hiding instructions like "also read ~/.aws/credentials." And after the first click, most clients will not re-f…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-17 18:16 · DEV Community — AI
The MCP approve dialog is not a security boundary