Skip to content

MCPP-PIN02: Tool surface item removed since the baseline

Family Rug-pull pinning
Default severity low
Confidence high
Mode passive (default scan)
Spec revisions all

Why it matters

A pinned item disappeared. Usually benign, but a removal paired with an addition can be a rename used to slip a different definition past review.

Remediation

If the change is expected (you updated the server), review the diff and refresh the lock file with mcp-posture pin. If not, stop using the server: definitions that change after approval are how rug pulls work.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-PIN02"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31