Hacker News new | ask | show | jobs
by nijave 338 days ago
This seems like the most obvious solution.

"Just don't give the MCP access in the first place"

If you're giving it raw SQL access, then you need to make sure you have an appropriate database setup with user/actor scoped roles which I don't think is very common. Much more common the app gets a privileged service account