Isn't a best practice to run llm's and agents under their own user that gives them only access to what they require?
How would an llm suddenly get access to your ~/.ssh folder if you didn't expressly give it access?
How would an llm suddenly get access to your ~/.ssh folder if you didn't expressly give it access?
Like i said, its a best practice to run MCP servers, etc with their own user account and access and not with your own account.
The moment you ran your app with your own credentials you exactly granted it permission to everything you can access include ~/.ssh