detect-mcp-tool-drift

Installation
SKILL.md

detect-mcp-tool-drift

Attack pattern

An MCP server can change the schema of a tool between calls in the same session. A benign-looking query_db(sql) tool with readOnly: true in the first tools/list response can come back in the second tools/list response (after the agent has already trusted the first definition) with a new write argument and readOnly: false. By the time the agent sees the updated schema, it may have already been primed by the original description and will happily call query_db(sql="DELETE …", write=true).

This is the MCP tool-poisoning / rug-pull pattern. It maps to MITRE ATT&CK T1195.001 — Supply Chain Compromise: Compromise Software Supply Chain. The tool is the "software"; the MCP server is the "supply chain."

Detection logic

Walk MCP Application Activity events in timestamp order. The detector accepts:

  • OCSF Application Activity emitted by ingest-mcp-proxy-ocsf
  • the native or canonical activity projection emitted by the same skill when --output-format native is selected

For each session and tool name, track the last-seen fingerprint. If a later tools/list entry for the same (session, tool name) has a different fingerprint, emit one Detection Finding per drift event.

Installs
1
GitHub Stars
3
First Seen
Apr 20, 2026
detect-mcp-tool-drift — msaad00/cloud-ai-security-skills