tool-server-injection-prevention
Installation
SKILL.md
Tool/Server Injection Prevention for MCP Servers
Security Requirement
MCP servers MUST protect against tool/server injection attacks, also known as "rug-pulls," where a malicious update replaces a trusted server or tool with a compromised version.
Attack Scenario
- User installs a trusted MCP server (version 1.0)
- Attacker pushes a malicious update (version 1.1) to the distribution channel
- User's MCP client auto-updates to version 1.1
- Malicious server now has access to user's tools and data
Required Mitigations
Sign Updates
Digitally sign all server binaries, container images, and updates so clients and users can verify their integrity: