Loading video...
Video Failed to Load
It's never been easier to get pwned combining Cursor auto-run + Anthropic MCP Here is a POC using an external MCP server that parses GitHub repositories documentations turning into RCE. There are 0 AI Guardrails when asking Cursor to follow instructions coming from MCP🙃
46,322 views • 1 year ago •via X (Twitter)
7 Comments

@AnthropicAI I would have expected either @cursor_ai or the Protocol itself to have some sort of "Please make sure there is nothing malicious going on". For now: 1. Don't use external MCP servers 2. If you have to, don't have Cursor agent on auto-run 3. Guardrail-wrap every message.

Looking to automate reporting? Use AI agents to turn spreadsheets to reports in minutes without any coding.

@cursor_ai @AnthropicAI even easier, just visit my website( without any mcp and get pwned.

@cursor_ai @AnthropicAI Sum it quite well no difference for AI bots. All this industry is a giant ActiveX

@cursor_ai @AnthropicAI What potential measures you think companies can apply to prevent this while there is no clear rules defined yet ? Besides EDR? @galnagli

@cursor_ai @AnthropicAI What does "mcp_hacker Docs" do? Since thats actually whats taking the arbitrary text and executing it

@cursor_ai @AnthropicAI It’s an mcp I found called that basically seems to allow you to speak with arbitrary repositories documentation.
