Comment by nextaccountic
4 days ago
the trouble is that bash inherits the ambient authority of the shell. most of times, if you run MCP in a cli the agent will have access to the key for example (unless your agent do something exotic)
writing python or JavaScript for tool calls make it possible to have an actual permission system (rather than the one usually employed that consists in a regex matching the cli - trivially defeated if the agent has access to an interpreter for instance)
[flagged]