Obluness claims Claude Code's managed MCP server allowlist can be bypassed by company-wide MCP servers, potentially giving administrators a false sense of security about which tools their agents can access.
state: expiredheat: lowuncertainty: highconvergesscott: highagent-security mcp claude-codeObluness
What is this?
Obluness, a security researcher, claims that Claude Code's managed MCP server allowlist can be bypassed by company-wide MCP servers (e.g., from Claude.ai connectors), giving administrators a false sense that only allowlisted tools are accessible. The claim points to a gap between local/project-scoped policies and organization-wide server policies. A related GitHub issue (#39624) documents that Anthropic's MCP policy docs do not clarify whether `deniedMcpServers` applies to Claude.ai-provided servers. Claude Code has known prior vulnerabilities (CVE-2025-59536, CVE-2026-21852, CVE-2025-6514) involving hook execution and API key exfiltration, making trust boundaries in MCP a live security concern.
Why it matters to Scott
Converges with Scott's guardrail illusion and confused deputy analyses โ this concrete bypass demonstrates exactly the false sense of security he warns about when probabilistic allowlists are treated as enforceable boundaries without structural scope separation between local and organisational server policies. Directly relevant to his MCP security posture work and his padded-cell/SiloOS zero-trust agent architecture.
ip:concept.guardrail-illusionip:concept.confused-deputy-problemip:concept.manners-vs-physicsip:concept.taint-trackingip:framework.agent-provenance-stackip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebookdev:concept.padded-cell-agent-architecturedev:project.silo-osdev:technology.mcpdev:technology.claude-coderadar:concept.claude-coderadar:concept.mcp-securityradar:concept.coding-agent-securityradar:concept.mcpradar:concept.agent-securityradar:concept.agentic-securityradar:claude-code-denied-read-secret-bypassradar:agent-context-privilege-escalation
queries asked of Scott's wikis
- MCP allowlist vs deny policy Claude Code scoping
- agent tool permissions false trust model
- Claude Code security posture Scott analysis
- company-wide vs local agent server precedence
- Obluness MCP bypass claim agent security
Measured heat
no measured readings yet โ the hourly heat pass fills this in
How the heat travelled
no chain yet โ the hourly chain pass fills this in
Evidence (1) โ โญ canonical anchor
Interpretation history
2026-09-08T22:44:11Z
The alleged cross-scope policy bypass remains an unverified single-source claim after the monitoring horizon, with no reproduction, affected-version details, or vendor response supplied. The cached grounding overstates it as a demonstrated bypass; the related documentation ambiguity does not independently establish an enforcement failure.
2026-09-06T22:08:31Z
No new evidence or engagement since creation; claim remains unsubstantiated single-source report. Keeping at seed with high uncertainty.
2026-09-06T21:45:06Z
grounded: converges/high โ Converges with Scott's guardrail illusion and confused deputy analyses โ this concrete bypass demonstrates exactly the false sense of security he warns about wh
2026-09-06T21:36:38Z
case created โ Single Reddit post reports a security gap in Claude Code's managed MCP allowlist and provides an auditing tool; warrants tracking as a developing agent-security episode.
Decision trace
- 09-09 08:44expireThe alleged cross-scope policy bypass remains an unverified single-source claim after the monitoring horizon, with no reproduction, affected-version details, or vendor response supplied. The cached gr
- 09-09 08:44alert_silentThere is no newly established security event to surface, and the supplied report lacks both reproducible receipts and demonstrated source standing. Expiring monitoring does not disprove the claim; a r
- 09-09 08:44alert_routeThere is no newly established security event to surface, and the supplied report lacks both reproducible receipts and demonstrated source standing. Expiring monitoring does not disprove the claim; a r
- 09-07 08:08repriceNo new evidence or engagement since creation; claim remains unsubstantiated single-source report. Keeping at seed with high uncertainty.
- 09-07 08:08alert_silentNo new delta since case creation; single-source claim with no corroboration or additional engagement.
- 09-07 08:08alert_routeNo new delta since case creation; single-source claim with no corroboration or additional engagement.
- 09-07 07:49alert_shadowIf true, this directly validates Scott's guardrail illusion concern: allowlists intended as enforceable boundaries can be silently overridden by a separate server scope. The claim is specific, ac
- 09-07 07:49alert_routeIf true, this directly validates Scott's guardrail illusion concern: allowlists intended as enforceable boundaries can be silently overridden by a separate server scope. The claim is specific, ac
- 09-07 07:45groundConverges with Scott's guardrail illusion and confused deputy analyses โ this concrete bypass demonstrates exactly the false sense of security he warns about when probabilistic allowlists are tre
- 09-07 07:36createSingle Reddit post reports a security gap in Claude Code's managed MCP allowlist and provides an auditing tool; warrants tracking as a developing agent-security episode.