Your AI agent just ran DELETE FROM users without a WHERE clause. It was trying to remove a single test account, hallucinated the query, and wiped your entire users table. No confirmation prompt, no rollback, no undo. Production is down and your backup is from last Tuesday. This is not a contrived scenario. The PostgreSQL MCP server gives AI agents exactly one tool — and that one tool is enough to destroy everything. One tool, infinite power Most MCP servers expose a handful of scoped tools. The

Your AI Agent Can Run DROP TABLE on Production
PolicyLayer
