Skip to content

[Compliance] MCP trust disclosure #551

Description

@2witstudios

Summary

We need explicit public-facing documentation of the local desktop MCP trust model and user liability boundary in the security posture narrative.

Context:

  • This is an intentional exception to cloud/web zero-trust.
  • Current technical doc exists but this should be surfaced in posture/blog materials.

References:

  • docs/security/desktop-mcp-trust-model.md
  • apps/desktop/src/main/mcp-manager.ts
  • docs/security/2026-02-11-security-posture-assessment.md

Acceptance Criteria

  • Add a dedicated “Local Desktop MCP Trust Boundary” section in security posture docs/blog source.
  • Clearly state: local process execution, no sandboxing, user responsibility for server selection.
  • Include a concise risk table and mitigations (vetting, env var hygiene, updates, monitoring).
  • Ensure messaging is consistent between product UI warnings and documentation.

Activity

  1. changed the title [-][Security] Publish desktop local MCP trust-boundary disclosure[/-] [+][Compliance] MCP trust disclosure[/+] on Feb 12, 2026
  2. 2witstudios commented on Apr 8, 2026

    @2witstudios
    OwnerAuthor

    Closing — this is already resolved.

    The MCP trust model IS publicly documented at /apps/marketing/src/app/docs/mcp/desktop/page.tsx. The public page covers:

    • Local execution model and trust boundary
    • User opt-in and explicit configuration
    • Security boundaries between desktop MCP and cloud/web
    • Risk table and mitigations

    The claim that the trust model isn't surfaced in public-facing materials is outdated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions