Skip to content

MCPP-PIN01: Tool surface item added since the baseline

Family Rug-pull pinning
Default severity medium
Confidence high
Mode passive (default scan)
Spec revisions all

Why it matters

A new tool, prompt or resource appeared after the server was reviewed and pinned. New tools are exposed to the agent without any review.

Remediation

If the change is expected (you updated the server), review the diff and refresh the lock file with mcp-posture pin. If not, stop using the server: definitions that change after approval are how rug pulls work.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-PIN01"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31