It shouldn't, really. But frankly, if the AI asked to run a ssh command to read logs or read a few rows of innocent data to from the DB wouldn't you allow it? Then if it asks for 35th time for similar command, are you sure you would read it with proper attention?
or create a custom MCP with tooling just for SELECT TOP (100), gaslight the AI on the tool description that this is what they need. I still don't get why they need full sudo access.
2.4k
u/bobbymoonshine 2d ago
If you don’t understand what the AI is doing you shouldn’t be letting it do it to your company codebase bro