Trust boundaries.
- MCP servers run with your user privileges (stdio) or as remote endpoints you configure.
- Only enable servers you trust.
- Review tool args before approving destructive operations.
- Do not put secrets in chat; use env blocks in
mcp.jsoncarefully.