mcp-trust-boundary-demo

volkthienpreecha
1
This repo shows a narrow security issue in MCP-style local stdio clients: server config can look like setup data, but it can function as execution authority on the local machine. The unsafe path trusts that config too far. The guarded path applies a small policy gate and blocks the same launch.

Content