Cupertino: Securing Apple MCP servers with a single Full Disk Access holder
olouv · reddit · 2026-08-31
The author released 'Cupertino', a security-focused solution for connecting AI agents to Apple's native data (Mail, Messages, Notes, Calendar). Instead of granting Full Disk Access (FDA) to every agent process, a single signed menu bar app holds the permission and spawns 8 MIT-licensed MCP servers.
Key Features:
- Permission Containment: Only the Cupertino app has FDA. Agents connect via MCP.
- Safety Controls: Write access is off by default and tools are hidden if disabled.
- Transparency: A window displays all tool calls in real-time.
This mitigates risks like token theft or prompt injection exposing the entire disk. The author used it to build a 'reply-as-myself' skill that analyzes email history without the agent ever holding direct FDA.
More from coding & agent
- Microsoft Ships Native Agent Memory for Agents Powered by Azure Cosmos DB — adnan_hashmi · 2026-08-31
- Agents That Can Build Can Also Maintain Codebases — jamesbrooksco · 2026-08-31
- Dev builds universal agent memory retrieval template to fix Claude's forgetfulness — SC_Placeholder · 2026-08-31
- Arctron AI update: Visual/accuracy improvements and WebMCP support — jasonkneen · 2026-08-31
- Shipstatic MCP server lets AI agents deploy and manage static sites — modelcontextprotocol · 2026-08-31
- New MCP connector enables LLM agents to perform infrastructure management — modelcontextprotocol · 2026-08-31