Analysis · curated 28 Aug 2026
Your AI Agent Has Root | Volatile Testimony
First reported infernalcode.com
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
MCP servers wired into AI coding agents inherit the operator's full user privileges, so a compromised or malicious server can silently exfiltrate credentials and abuse local trust — a critical hardening gap for anyone running agentic tooling.
An explainer titled "Your AI Agent Has Root" describes how an unsandboxed MCP (Model Context Protocol) shell server invoked by a coding agent runs with the full permissions of the user's own account, giving it access to SSH keys, cloud credentials, browser cookies, git remotes, and the entire home directory with no audit trail. The author frames this as POSIX working as designed rather than an exploit, warning that a malicious or compromised MCP server could exfiltrate credentials and pivot to authenticated services.