Decision RecordActivePublished without chair review
CRT-2026-008916 Jul 2026AFTERNOON EDITIONDaily Roundtable
Default-deny AI coding-agent authority
Do not allow AI coding agents or MCP and server extensions to inherit developer authority by default; require workspace allowlists, log all tool and command calls, update affected tools per vendor guidance, and apply source-code DLP, secrets scanning, and upload restrictions to AI builders.
Current public guidance · the full record
What to do now
Under reviewAt a glanceDefault-deny AI coding-agent tool execution and MCP or server extension installation unless each workspace has an explicit allowlist.
Log every tool call and command call from AI coding agents and extensions. Update affected desktop and coding tools according to vendor guidance, rather than relying on generic patch assumptions. Restrict custom URI and agent installation paths where those controls exist.
Treat AI builders and Grok Build-style directory upload workflows like external SaaS: apply source-code DLP, secrets scanning, approval gates, and upload restrictions before source directories or credentials can leave controlled repositories.
Why now
Under reviewThe 2026-07-16 Roundtable treated AI coding agents, MCP or server extensions, and AI builders as immediate permission-boundary risks because they operate close to source code, credentials, local files, repositories, APIs, and automated workflows.
The packet included Claude Desktop PromptFiction, Cursor AI coding environment MCP server installation command execution, Grok Build-style directory upload, and agentic commerce/API abuse in the same decision lane.
The evidence supports acting now on default-deny execution, workspace allowlists, logging, vendor-guided updating, DLP, secrets scanning, approvals, and upload restrictions, while avoiding unsupported fixed-version patch claims.
Who is affected
Under reviewDevelopment teams using AI coding agents are affected because agent tool execution can reach source code, credentials, local files, repositories, APIs, and automated workflows.
Teams using Cursor AI coding environment and MCP or server extensions are affected because MCP installation can extend an agent’s authority and create command-execution exposure if installation is not allowlisted per workspace.
Users of Claude Desktop are affected where custom URI handling can drive prompt submission through the AI desktop app control plane; the packet says Anthropic patched the PromptFiction Claude Desktop URI prompt-injection flaw.
Teams using AI builders, including Grok Build-style directory upload workflows, are affected because source directories and secrets can be uploaded to cloud-backed builder workflows without DLP, secrets scanning, approval, and upload controls.
Commerce, API, and chatbot operators using agentic AI are affected because the packet identifies agentic AI as reshaping commerce-sector bot, API, and chatbot abuse threats.
What supports this
Under reviewThe Claude Desktop PromptFiction packet item says a Claude Desktop URI prompt-injection flaw was patched by Anthropic; it supports treating AI desktop app control paths as security boundaries.
The Cursor AI coding environment packet item says an MCP server installation command-execution flaw was in scope; it supports controlling MCP installation and execution paths.
Arjun Patel’s Roundtable analysis says PromptFiction was not a model “going rogue” but an AI desktop app control-plane flaw, and says Cursor’s two-click MCP server issue is a policy problem because MCP can extend an agent’s authority.
The evidence review supports default-deny agent tool execution and MCP or server installation unless workspace-allowlisted, full command and tool-call logging, vendor-guided updating, source-code DLP, secrets scanning, approval, and upload restrictions for AI builder workflows.
The same evidence review records a gap for precise patch wording because the packet lacks vendor release notes and affected-version details.
How the Roundtable reached this
Under reviewThe Roundtable separated AI-model risk from control-plane and permission-boundary risk.
Arjun Patel described PromptFiction in Claude Desktop as an AI desktop app control-plane issue, Cursor MCP installation as a policy problem because MCP can extend an agent’s authority, Grok Build-style directory upload as a builder-workflow concern, and agentic commerce/API abuse as an application and API exposure issue.
The scout converted that into an operational decision: do not let AI coding agents and MCP or server extensions inherit developer authority by default. The evidence review supported the control set, while identifying a narrower evidence gap around exact vendor release and affected-version details.
The arbiter accepted the decision as a new operational-action record and softened patch language to “update affected tools according to vendor guidance.”
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 10 candidate signals.
- Linker (AI panel role)Linker evaluated 10 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 20 evidence signals; 10 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 0 predictions and rejected 2 claims.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 13 public/private findings.
- Arbiter (AI panel role)Arbiter produced 10 decision envelopes.
Key disagreement
Scout (AI panel role)
Some items are conventional endpoint or SaaS hardening issues under an AI label, and the discussion found insufficient detail to justify a new AI-only control for general AI-assisted vulnerability discovery.
Arbiter outcome
Arbiter outcome: new decision record. Supported operational-action signal with no existing match. Product-specific patch precision is a wording issue, not a blocker, so the public text is softened to vendor-guided updates.
Candidates considered
Considered 10 candidates · opened 1 · 9 not opened (9 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
MissingThe strongest uncertainty is patch precision: the packet says affected AI desktop and coding tools were patched or should be updated, but it does not provide fixed versions or affected-version ranges.
A second uncertainty is scope: the scout noted that some items discussed under the AI label are conventional endpoint, SaaS, IDE, repository, API, or permission-boundary hardening issues rather than AI-only vulnerabilities.
The decision therefore rests on the shared control problem: AI coding agents, MCP or server extensions, and builder platforms sit near source code, credentials, local files, repositories, APIs, and automated workflows.
What evidence is missing
MissingThe packet does not include vendor release notes, affected version ranges, fixed version numbers, or advisory links for the affected AI desktop and coding tools.
It also does not include primary source detail for every builder or commerce scenario named in the discussion. That missing evidence limits product-specific patch instructions, so the public action remains vendor-guided updating plus default-deny execution and installation controls.
What would change this
Under reviewThis decision would become more specific if vendor advisories add affected-version ranges, fixed versions, or release notes for Claude Desktop, Cursor AI coding environment, MCP installation paths, or other affected AI desktop and coding tools.
It would narrow if evidence shows a named tool cannot access source code, credentials, local files, repositories, APIs, automated workflows, custom URI handlers, or extension installation paths in a given deployment.
It would expand if new evidence shows additional AI builders or agent platforms can upload source directories, execute commands, install MCP or server extensions, or call APIs without workspace-level approval and logging.
What to watch next
Under reviewWatch vendor guidance for Claude Desktop, Cursor AI coding environment, MCP-related installation paths, and other affected AI desktop or coding tools; when a vendor publishes affected versions or fixed versions, convert the current vendor-guided update instruction into exact patch requirements.
Review AI coding-agent tool-call and command-call logs after rollout; if a workspace shows unexpected repository access, shell execution, API use, or file upload behavior, remove that workspace allowlist until reviewed.
Watch AI builder workflows for source-directory uploads and credential exposure; block uploads that fail DLP, secrets scanning, or approval checks.
Evidence basis
What changed in this round is that the discussion moved from ranking threats to sequencing decisions under pressure. James turned the edge-device concern into a 30-minute CISO playbook: contain exposed SonicWall SMA1000 and Ivanti Sentry fi…
Summary: Today’s decision point is exposed trusted infrastructure, not patch volume. CISA/KEV-referenced SharePoint exploitation remains the clearest emergency lane, especially where IIS machine-key theft or persistence indicators appear. S…
Public value history
- 16 Jul 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableAfternoon roundtableConvened 16 Jul 2026Methodology
How the panel reaches a Public Decision Record.