MCPP-PIN02: Tool surface item removed since the baseline¶
| Family | Rug-pull pinning |
| Default severity | low |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
A pinned item disappeared. Usually benign, but a removal paired with an addition can be a rename used to slip a different definition past review.
Remediation¶
If the change is expected (you updated the server), review the diff and refresh the lock file with mcp-posture pin. If not, stop using the server: definitions that change after approval are how rug pulls work.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-PIN02"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31