-
Notifications
You must be signed in to change notification settings - Fork 90
Closed
Description
Question
I received a popup from the latest update informing me the new MCP server was on by default. From my reading of it, it will start automatically and connects to the active connection.
Is this a sensible default from a security perspective?
Particularly with "mdb.mcp.readOnly": false
being the default, this feels like existing users of the extension, with preconfigured connections are suddenly getting a new risk avenue open that they may not fully understand.
Additional context
New MCP changes were merged with #1115
Metadata
Metadata
Assignees
Labels
No labels