remediate-mcp-tool-quarantine
Installation
SKILL.md
remediate-mcp-tool-quarantine
What this closes
Pair skill for both shipped MCP detectors:
detect-mcp-tool-drift— T1195.001 Compromise Software Supply Chain (the rug-pull / tool-poisoning pattern where an MCP tool's behavior or schema mutates between calls)detect-prompt-injection-mcp-proxy— MITRE ATLAS AML.T0051 Prompt Injection (suspicious natural-language patterns in tool descriptions designed to override agent instructions)
Closes #155 phase 2: 2 of 8 detection gaps in one skill, the AI-native loop. After this PR ships, 5 of 11 detections are closed-loop.
Why file-based quarantine
The MCP attack surface is in-process from the agent's POV — there's no cloud API to call to "block a tool." The cleanest, surface-neutral remediation is a structured JSONL quarantine file that the operator's MCP client reads at startup (or via hot-reload) to filter its tool surface:
- MCP servers in this repo can read it via
CLOUD_SECURITY_MCP_QUARANTINED_TOOLS_FILE(operators wire this in their.mcp.json). - Third-party MCP clients (Claude Code / Desktop, Codex, Cursor, Windsurf, etc.) can wire it via their per-client allow/deny config — the file is the protocol.
Each line of the file is one quarantine entry with tool_name, session_uid, fingerprint, producer_skill, finding_uid, incident_id, approver, quarantined_at. The MCP client filters its discoverable tool list against this on startup.