From MCP to shell: MCP auth flaws enable RCE in Claude Code, Gemini CLI and more