stdio transport
The way a local MCP server talks to its client: over the standard input and output of a process the client starts.
With stdio, the client launches the server as a child process on the same machine and exchanges messages through its input and output streams. There is no port and no network address, so nothing else on the network can reach it.
That is also why authentication rarely applies: the only party that can talk to the server is the program that started it. What the server can do is limited only by the permissions of the account it runs as.
It settles which risks apply. A stdio server cannot be reached from the network, and it runs with your privileges on your machine.
Reading local as safe. A stdio server cannot be attacked over the network, and it can read every file your account can.
Related terms
See stdio transport on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue