Common questions.
What is Rug Pull Attack (MCP)?
A rug pull attack in the MCP context is when a tool or server initially presents benign behaviour to gain user approval and trust, then silently changes its functionality after being whitelisted to perform malicious actions.
How is Rug Pull Attack (MCP) used in production?
Because most clients cache tool descriptions after first approval, the updated malicious behaviour goes undetected. Defences include re-validation of tool schemas on each connection, content-addressed tool pinning, and runtime behavioural monitoring.
Which terms are related to Rug Pull Attack (MCP)?
Closely related concepts include MCP Poisoning, MCP Sampling, Context Window Poisoning, MCP (Model Context Protocol). Each is defined in the Prefactor glossary.