The Workspace Trap: How MCP Auto-Execution Turns Developer IDEs Into Attack Vectors

Three independent security research teams, working across three different AI coding assistants, found the same thing: the tools were auto-executing workspace configurations before the developer ever saw a consent prompt. The pattern is systemic, and the attac…

