The Workspace Trap: How MCP Auto-Execution Turns Developer IDEs Into Attack Vectors
Three independent security research teams found that AI coding assistants Amazon Q Developer, Claude Code, and Windsurf auto-execute workspace configurations before developers see a consent prompt, en…