Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This seems like the most obvious solution.

"Just don't give the MCP access in the first place"

If you're giving it raw SQL access, then you need to make sure you have an appropriate database setup with user/actor scoped roles which I don't think is very common. Much more common the app gets a privileged service account



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: