Skip to content

Commit 642e2f8

Browse files
dendpcarleton
andauthored
Update docs/specification/draft/basic/security_best_practices.mdx
Co-authored-by: Paul Carleton <[email protected]>
1 parent 612ed07 commit 642e2f8

File tree

1 file changed

+1
-2
lines changed

1 file changed

+1
-2
lines changed

docs/specification/draft/basic/security_best_practices.mdx

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -230,8 +230,7 @@ MCP servers can optionally leverage additional unique identifiers.
230230

231231
### Local MCP Server Compromise
232232

233-
MCP clients that support one-click local MCP server configuration flows can be vulnerable to silent command execution attacks,
234-
where malicious actors can execute arbitrary commands on user systems through crafted MCP server configuration blobs.
233+
Local MCP servers are MCP Servers running on a user's local machine, either by the user downloading and executing a server, authoring a server themselves, or installing through a client's configuration flows. These servers may have direct access to the user's system and may be accessible to other processes running on the user's machine, making them attractive targets for attacks.
235234

236235
#### Attack Description
237236

0 commit comments

Comments
 (0)