MCP - User discovered excessive permissions exposed by MCP inte...

User discovered excessive permissions exposed by MCP integrations, including ability to execute arbitrary SQL and delete repositories.

Updated: 4/15/2026
I tried something simple last month. Connected a Postgres MCP to one of our bots. Wanted read access. The server also exposed DELETE, execute arbitrary SQL, and DROP TABLE. GitHub MCP — added for code reading. Also had delete_repository. Slack MCP — wanted search. Got https://t.co/1gDzJiJD2C Source: https://x.com/navinsharmacse/status/2037162035084202060

Did this solve your problem?

0 developers found this helpful