Summary
Desktop MCP manager is explicitly trust-based and unsandboxed, which conflicts with blanket “zero trust architecture” claims unless documented as an exception.
Why this is a liability
Security posture mismatch between product messaging and actual execution model can lead to incorrect operator assumptions.
Current behavior (evidence)
apps/desktop/src/main/mcp-manager.ts notes:
- Trust-based model
- No sandboxing/command restrictions
Risk / impact
- Users/admins may overestimate isolation guarantees.
- Increases blast radius of malicious or compromised local MCP commands.
Proposed remediation
- Update architecture/security docs and UI language to explicitly call out desktop MCP trust boundary exception.
- Add explicit opt-in warnings and least-privilege guidance for MCP server configuration.
- Optionally evaluate sandboxing roadmap for desktop MCP process execution.
Acceptance criteria
- Public/internal security docs clearly distinguish zero-trust server model vs trusted local desktop MCP model.
- UI setup path includes clear warning and risk acknowledgment.
- Security review sign-off confirms messaging matches implementation.
Summary
Desktop MCP manager is explicitly trust-based and unsandboxed, which conflicts with blanket “zero trust architecture” claims unless documented as an exception.
Why this is a liability
Security posture mismatch between product messaging and actual execution model can lead to incorrect operator assumptions.
Current behavior (evidence)
apps/desktop/src/main/mcp-manager.tsnotes:Risk / impact
Proposed remediation
Acceptance criteria