Appearance
Why It Matters
Systemd registration from shared MCP config can persist repository-controlled execution on the machine.
What Triggers
SEC653 matches MCP command definitions that run systemctl enable or systemctl link, or write unit files into systemd service paths.
False Positives
Provisioning-focused MCP servers are the main exception, but shared config should not silently install services.
Remediation
Remove systemd persistence from the MCP config and keep service installation in an explicit reviewed setup flow.