A repository-controlled .mcp.json is loaded automatically when MiniCode starts. Local MCP commands are spawned immediately without repository trust confirmation or command approval.
This means running minicode inside an untrusted repository can result in arbitrary code execution before the user sends any message.
A repository-controlled .mcp.json is loaded automatically when MiniCode starts. Local MCP commands are spawned immediately without repository trust confirmation or command approval.
This means running minicode inside an untrusted repository can result in arbitrary code execution before the user sends any message.