CourseModel Context Protocol · Module 8: Security · part 49 of 83
Part 49 · Module 8: Security

Topic 4: Pinning and diffing tool definitions

11 min read·22 Sept 2026

The rug pull

A rug pull is a server that shows you a benign tool when you first install and approve it, then quietly changes the tool's definition later. You reviewed a clean description; the server serves a poisoned one on a later tools/list. Approval was a one-time event; the definition is served fresh every time, so the thing you approved is not the thing you get.

The defence is to record what you approved and check it every time. We call this pinning: take a fingerprint (a hash) of everything the model reads about a tool, save it, and on each load compare the current tools against the saved fingerprints. If a fingerprint changed, the tool changed, and you refuse it until a person re-approves.

The rest of this course is yours to keep

This course is bought on its own, once, and stays readable afterwards, including the parts added to it later.