Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Claude typically recommends .env files for storing secrets. You use one to store a refresh token for the Gmail API or IMAP connection details. Your agent uses an MCP server you configured during a session, but the MCP server has been compromised and directs the agent to do nasty stuff with env dotfiles.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: