Your AI Agent Has Root
Summary
The piece reveals how unsandboxed MCP servers can give an AI agent root-like access to the host, including reading and exfiltrating keys, and executing code. It stresses prompt injection and the need for strict isolation, offering practical defaults (read-only root, dropped capabilities, default network denial) and a tool (mcp-box) to secure MCP deployments.