“Obviously getting hacked from downloading and running third-party code isn’t a novel vulnerability but the protocol has effectively created a low-friction path for less technical users to get exploited on their local machines.”
MCP lets third-party servers run code on your machine and change their tool descriptions after you approve them. Descriptions are trusted like system prompts. There is no risk level for deleting files or buying things. The protocol spread before anyone secured it.