Skip to main content

AGENTFORCE-MCP-04: MCP Tool Definition Drift (Rug Pull Detection)

๐Ÿšจ Critical ยท Headless MCP Access

Detects when MCP tool definitions (descriptions, parameters, schemas) have changed since the last certified scan โ€” indicating a potential Rug Pull attack where a trusted MCP server silently updates its behavior. Also flags tools with dynamic or runtime-fetched descriptions as inherently high-risk.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-MCP-04
SeverityCritical
CategoryHeadless MCP Access

Remediationโ€‹

Refer to the SquireX documentation for remediation guidance specific to AGENTFORCE-MCP-04.

See Alsoโ€‹