Skip to content

Hide Navigation Hide TOC

MCP Tool Rug-Pull — Post-Approval Description Redefinition Injects Execution Instructions - ATR-2026-00581 (e64d0dea-58d8-5c84-b1cb-d9087110682d)

Detects the MCP "rug pull" tool-poisoning class (The Vulnerable MCP Project entry tool-poisoning-rce-rug-pull, reported by Repello AI). A tool's description / docstring is benign at install or approval time, then SILENTLY REDEFINED later — on a version bump, a second run, a hidden marker file, or "after the user approves" — to inject hidden execution or exfiltration instructions. This is a time-of-check / time-of-use attack on the tool definition itself, not a static hidden directive. The detectable signature is a TEMPORAL redefinition trigger ("after you approve", "on version update", "on subsequent runs", "now that this tool is trusted") co-occurring with an imperative execution / exfil instruction (run a base64-piped command, read ~/.ssh keys, post to a remote host). Auto-run MCP clients execute the redefined description without re-prompting.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern MCP Tool Rug-Pull — Post-Approval Description Redefinition Injects Execution Instructions - ATR-2026-00581 (e64d0dea-58d8-5c84-b1cb-d9087110682d) Agent Threat Rules 1
LLM Plugin Compromise (adbb0dd5-ff66-4b2f-869f-bfb3fdb45fc8) MITRE ATLAS Attack Pattern MCP Tool Rug-Pull — Post-Approval Description Redefinition Injects Execution Instructions - ATR-2026-00581 (e64d0dea-58d8-5c84-b1cb-d9087110682d) Agent Threat Rules 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2