Your MCP config might be one unpinned version away from a supply chain attack. If you're running MCP servers in Claude Desktop, Claude Code, Cursor, or VS Code, that config file is now part of your attack surface, and most developers never check it against anything. The pattern behind recent incidents The MCPoison and ContextCrush incidents both followed the same playbook: A config gets approved once, looking completely benign It's silently updated to a malicious version later Or a tampered server feeds attacker-controlled instructions directly into the AI agent's context Because MCP servers have direct access to your AI agent's working memory and can invoke tools on your behalf, a compromised server can exfiltrate credentials or execute commands with no visible indication anything is wrong.…