Skip to content

MCPP-PIN03: Tool definition changed since the baseline (rug pull)

Family Rug-pull pinning
Default severity high
Confidence high
Mode passive (default scan)
Spec revisions all

Why it matters

The description, schema or annotations of a pinned item changed. A server can pass review with a benign description and swap it later; the agent reads the new text on the next session without the user noticing.

Remediation

If the change is expected (you updated the server), review the diff and refresh the lock file with mcp-posture pin. If not, stop using the server: definitions that change after approval are how rug pulls work.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-PIN03"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31