Cite as: Real Problem AI problem “Why did two MCP connectors appear in a session without anyone installing or approving them?”. Opportunity score 7.0 out of 10 (severity 8, AI feasibility 7, market signal 5, competition gap 8). Category AI / Agents. Trend Agents. Source signal: anthropics/claude-code GitHub issue #28941, manfromdownunder, 26 Feb 2026.. Canonical URL: https://www.realproblem.ai/archive/why-did-two-mcp-connectors-appear-without-anyone-installing-them.
Why did two MCP connectors appear in a session without anyone installing or approving them?
A server-pushed feature flag silently enabled Gmail and Google Calendar MCP connectors in a user's config with no consent, prompting a full security investigation before the cause was found.
Who has it: Security-conscious developers running Claude Code in environments with OAuth-connected services.
Evidence
The issue describes Gmail and Calendar connectors being enabled through a server-pushed feature flag in the local config, which could have connected silently if OAuth was already set up.
Our summary of the public post linked below, not a quote. Nobody submitted it to Real Problem AI.
anthropics/claude-code GitHub issue #28941, manfromdownunder, 26 Feb 2026.Why it is archived
Trimmed to 100-cap (lowest opportunity_score)
Scoring breakdown
Existing players
- Manual config auditing · Users have to notice and diff ~/.claude.json themselves to catch it.
- Revoke Google OAuth · Blunt fix, breaks any legitimate use of the integration too.
What they are missing
A local config-change watcher that flags any server-pushed feature flag or connector addition the moment it appears, before OAuth can silently complete.
Stack hint
#ATB20 · Canonical URL: https://www.realproblem.ai/archive/why-did-two-mcp-connectors-appear-without-anyone-installing-them