Tool drift, or the rug pull
Checked at call timeA server passes review, an agent is authorised against it, and the tool's schema or description changes afterwards.
The digest in force when the agent was authorised is compared against the digest at the moment of the call. A scan on Monday says nothing about a call on Thursday; only a check at the call can.
Tool poisoning
CoveredA manipulated tool description steers the agent into leaking data or taking an action nobody asked for.
Descriptions are scanned, and the description is part of the digest above — so poisoning an approved tool is also drift.
A poisoned result
CoveredContent authored by a third party arrives as trusted context through a tool the agent was allowed to call.
Results are evaluated on the tool_result surface and the taint is propagated, so an argument later derived from that text cannot exceed the ceiling for tool-sourced data.
An undeclared tool
Becomes a findingThe agent calls a tool nobody registered. Hygiene scanning never sees it, because nobody pointed a scan at that server.
It is recorded as an observed tool and raised as a discovery finding — visible rather than invisible. The first call is still the first call, and we do not pretend otherwise.
An over-scoped server
PartlyOne server can read sensitive data or trigger destructive actions far beyond what the agent using it needs.
Impact inference and the capability ceiling bound what any single call can do. What we do not yet say is 'this server can do far more than this agent has ever needed', which is the posture finding worth having.
Credential sprawl
Not coveredEvery agent holds its own upstream credentials, multiplying the blast radius of any one leak.
We do not broker or hold upstream credentials, so we cannot consolidate them. Listed because it is a real MCP risk and leaving it out would make this table a sales sheet.