2026-10-11 18:02 UTC

Obluness claims Claude Code's managed MCP server allowlist can be bypassed by company-wide MCP servers, potentially giving administrators a false sense of security about which tools their agents can access.

state: expiredheat: lowuncertainty: highconvergesscott: highagent-security mcp claude-codeObluness

What is this?

Obluness, a security researcher, claims that Claude Code's managed MCP server allowlist can be bypassed by company-wide MCP servers (e.g., from Claude.ai connectors), giving administrators a false sense that only allowlisted tools are accessible. The claim points to a gap between local/project-scoped policies and organization-wide server policies. A related GitHub issue (#39624) documents that Anthropic's MCP policy docs do not clarify whether `deniedMcpServers` applies to Claude.ai-provided servers. Claude Code has known prior vulnerabilities (CVE-2025-59536, CVE-2026-21852, CVE-2025-6514) involving hook execution and API key exfiltration, making trust boundaries in MCP a live security concern.

Why it matters to Scott

Converges with Scott's guardrail illusion and confused deputy analyses โ€” this concrete bypass demonstrates exactly the false sense of security he warns about when probabilistic allowlists are treated as enforceable boundaries without structural scope separation between local and organisational server policies. Directly relevant to his MCP security posture work and his padded-cell/SiloOS zero-trust agent architecture.
ip:concept.guardrail-illusionip:concept.confused-deputy-problemip:concept.manners-vs-physicsip:concept.taint-trackingip:framework.agent-provenance-stackip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebookdev:concept.padded-cell-agent-architecturedev:project.silo-osdev:technology.mcpdev:technology.claude-coderadar:concept.claude-coderadar:concept.mcp-securityradar:concept.coding-agent-securityradar:concept.mcpradar:concept.agent-securityradar:concept.agentic-securityradar:claude-code-denied-read-secret-bypassradar:agent-context-privilege-escalation
queries asked of Scott's wikis
  • MCP allowlist vs deny policy Claude Code scoping
  • agent tool permissions false trust model
  • Claude Code security posture Scott analysis
  • company-wide vs local agent server precedence
  • Obluness MCP bypass claim agent security

Measured heat

no measured readings yet โ€” the hourly heat pass fills this in

How the heat travelled

no chain yet โ€” the hourly chain pass fills this in

Evidence (1) โ€” โญ canonical anchor

sourceobjectauthorscorecomments
๐ŸŸ  reddit โญIf you use Claude Code + MCP (GitHub Copilot MCP, Sentry, etc.) under managed settings, your allowlist may be a false sense of security
ClaudeAI
Obluness11

Interpretation history

Decision trace