Cupertino: Securing Apple MCP servers with a single Full Disk Access holder

olouv · reddit · 2026-08-31

The author released 'Cupertino', a security-focused solution for connecting AI agents to Apple's native data (Mail, Messages, Notes, Calendar). Instead of granting Full Disk Access (FDA) to every agent process, a single signed menu bar app holds the permission and spawns 8 MIT-licensed MCP servers.

Key Features:

This mitigates risks like token theft or prompt injection exposing the entire disk. The author used it to build a 'reply-as-myself' skill that analyzes email history without the agent ever holding direct FDA.

Original post →

More from coding & agent

coding & agent channel →