remediate-mcp-tool-quarantine

Installation
SKILL.md

remediate-mcp-tool-quarantine

What this closes

Pair skill for both shipped MCP detectors:

  • detect-mcp-tool-drift — T1195.001 Compromise Software Supply Chain (the rug-pull / tool-poisoning pattern where an MCP tool's behavior or schema mutates between calls)
  • detect-prompt-injection-mcp-proxy — MITRE ATLAS AML.T0051 Prompt Injection (suspicious natural-language patterns in tool descriptions designed to override agent instructions)

Closes #155 phase 2: 2 of 8 detection gaps in one skill, the AI-native loop. After this PR ships, 5 of 11 detections are closed-loop.

Why file-based quarantine

The MCP attack surface is in-process from the agent's POV — there's no cloud API to call to "block a tool." The cleanest, surface-neutral remediation is a structured JSONL quarantine file that the operator's MCP client reads at startup (or via hot-reload) to filter its tool surface:

  • MCP servers in this repo can read it via CLOUD_SECURITY_MCP_QUARANTINED_TOOLS_FILE (operators wire this in their .mcp.json).
  • Third-party MCP clients (Claude Code / Desktop, Codex, Cursor, Windsurf, etc.) can wire it via their per-client allow/deny config — the file is the protocol.

Each line of the file is one quarantine entry with tool_name, session_uid, fingerprint, producer_skill, finding_uid, incident_id, approver, quarantined_at. The MCP client filters its discoverable tool list against this on startup.

Installs
1
GitHub Stars
3
First Seen
Apr 20, 2026
remediate-mcp-tool-quarantine — msaad00/cloud-ai-security-skills