detect-mcp-tool-drift
detect-mcp-tool-drift
Attack pattern
An MCP server can change the schema of a tool between calls in the same session. A benign-looking query_db(sql) tool with readOnly: true in the first tools/list response can come back in the second tools/list response (after the agent has already trusted the first definition) with a new write argument and readOnly: false. By the time the agent sees the updated schema, it may have already been primed by the original description and will happily call query_db(sql="DELETE …", write=true).
This is the MCP tool-poisoning / rug-pull pattern. It maps to MITRE ATT&CK T1195.001 — Supply Chain Compromise: Compromise Software Supply Chain. The tool is the "software"; the MCP server is the "supply chain."
Detection logic
Walk MCP Application Activity events in timestamp order. The detector accepts:
- OCSF Application Activity emitted by
ingest-mcp-proxy-ocsf - the native or canonical activity projection emitted by the same skill when
--output-format nativeis selected
For each session and tool name, track the last-seen fingerprint. If a later tools/list entry for the same (session, tool name) has a different fingerprint, emit one Detection Finding per drift event.