MCP Tool Poisoning, Impersonation, or Rug Pull
A trusted MCP server, tool definition, OAuth scope, command, package, certificate, or endpoint changes unexpectedly, or an agent invokes a tool whose effective behavior no longer matches approval.
Trigger: A trusted MCP server, tool definition, OAuth scope, command, package, certificate, or endpoint changes unexpectedly, or an agent invokes a tool whose effective behavior no longer matches approval.
Severity guide: Severity 1 when a changed tool can access secrets, code, customer data, cloud control planes, or execute commands.
First 15 minutes
- Disable or quarantine the affected MCP server or tool at the gateway or agent configuration.
- Preserve approved and current manifests, hashes, package versions, certificates, and tool descriptions.
- Identify agents, users, and sessions that loaded or invoked the changed tool.
- Block high-risk tool actions while preserving read-only telemetry.
- Open a supply-chain and agent-trajectory investigation.
First 60 minutes
- Diff server endpoint, command, arguments, environment, OAuth scopes, tool name, description, input schema, package digest, and certificate.
- Reconstruct every tool invocation after the earliest known drift.
- Correlate downstream file, process, network, repository, secret, and cloud effects.
- Check whether an untrusted server impersonated a trusted name or tool.
- Determine whether the change was a legitimate release, dependency compromise, account takeover, or malicious rug pull.
- Notify the server owner and package or registry provider.
Evidence checklist
- approved and current MCP configurations
- server and tool hashes
- package and container digests
- certificate and DNS state
- agent sessions and tool-call arguments
- OAuth scopes and credentials used
- process, file, network, repository, and cloud effects
- change-management records and release signatures
Containment options
- quarantine server or tool
- revoke related OAuth grants and credentials
- pin trusted version and digest
- block unapproved endpoints and certificates
- disable high-risk actions across affected agents
- restore from signed baseline
- isolate impacted hosts or containers when execution occurred
Recovery and durable controls
- tool-definition integrity baseline
- signed manifests and pinned dependencies
- allowlisted server identities and endpoints
- least-privilege OAuth scopes
- approval on material tool changes
- continuous MCP drift detection and canary replay
Communications
- Engineering and product own service restoration.
- Security owns scope and trajectory reconstruction.
- Legal and procurement join for third-party or marketplace compromise.
- Customers are notified only after scope and data impact are defensible.
Closure criteria
- Trusted baseline is restored and verified.
- All affected trajectories are reviewed or bounded.
- Credentials and OAuth grants are remediated.
- Drift analytic fires on a controlled change.
- Material tool updates require re-authorization.
Required conversion to practice
Before closure, produce:
- one updated attack-path or trajectory diagram
- one root-cause finding
- one production or candidate hunt analytic
- one safe replay or regression test
- one remediation-validation memo
- one owner and residual-risk decision
How to use these. They are generic by design: they do not know your environment, your provider, or your legal obligations. Free to use and adapt inside your organization; keep the source line if you republish. Version 1.0, 27 August 2026. Every runbook ends with the same rule: before closure, convert the incident into a diagram, a root-cause finding, a hunt analytic, a regression test, a validation memo, and an owner. That conversion is the part most teams skip, and it is the part we are hired for.
- Leaked AI or Model API Credential
- Inference Cost Spike or Token-Jacking
- Persistent Memory or RAG Poisoning
- Unauthorized Agent Action or Data Exfiltration
- Shadow or Exposed AI Infrastructure
- Malicious Model, Artifact, Skill, Plugin, or Extension
- Confidential or Sovereign AI Boundary Failure
- AI Provider or Model Gateway Third-Party Incident
- AI Coding Agent Repository or CI Compromise
Happening now?
Send a project inquiry and set timing to active incident. Joey Victorino reads those first and answers the same business day, US Pacific. Put no credentials, prompts, or customer data in the form.