A few days ago, a devops engineer posted on r/devops:


"MCP servers just showed up in our infrastructure and I genuinely have no idea how to secure them, anyone been through this?"


Filesystem access, shell permissions, database connectors - all callable by agents without human approval. At the time I'm writing this, the thread has 76 upvotes...