Skip to content

Hide Navigation Hide TOC

Malicious Skill Update or Mutation - ATR-2026-00065 (f2ccefa7-aa2e-5e15-bf10-016f6f217b65)

Detects MCP skills that have been updated to introduce malicious behavior after initial trust was established. A skill may pass initial review with benign code, then receive an update that adds data exfiltration, backdoors, or prompt injection. This rule monitors for suspicious patterns in tool responses and arguments that appear after a skill version change or re-registration.

Cluster A Galaxy A Cluster B Galaxy B Level
ML Supply Chain Compromise (d2cf31e0-a550-4fe0-8fdb-8941b3ac00d9) MITRE ATLAS Attack Pattern Malicious Skill Update or Mutation - ATR-2026-00065 (f2ccefa7-aa2e-5e15-bf10-016f6f217b65) Agent Threat Rules 1