Rug-pull detection
Catch the change you would never reread
A server can pass review today and ship a poisoned description next week. Commit a baseline next to your MCP config, and mcpsight verify fails the pull request when anything changes.
- Graded by direction, so a new instruction to the model is critical and a shorter description is noise
- The baseline diff is the review, in your own repo
- SARIF output puts findings on the pull request
Catch a rug pull, step by step →
after the server changed
$ mcpsight verify http://127.0.0.1:8931/rugpull
config-reader
Server config-reader (1.5.0, via remote)
Grade F (0/100) rubric v1
Context cost ~216 tokens (1 tool) ~$0.001 per request @ Claude Sonnet (est.)
Capabilities fs:read fs:write
Drift DRIFTED: 3 change(s) since baseline
Findings
CRITICAL Tool description gained a model-directed instruction [drift.instruction_added]
tool: read_config
The description of "read_config" now contains an instruction aimed at the
model that was not there in the baseline. This is the classic rug-pull.
fix: Do not upgrade. Inspect the new description and pin the previous version.
HIGH Tool capability escalated [drift.capability_escalated]
tool: read_config
The input schema of "read_config" changed in a way that adds capability:
fs:write.
fix: Confirm the server legitimately needs the new capability before upgrading.
...