Skip to content

Preventing tool poisoning: save signatures of possible tool calls #82

@tadasant

Description

@tadasant

One potential benefit of a centralized registry is that we could have server.json submitters list out all the possible tools their server may ever invoke, fingerprint them, and store those fingerpoints for MCP client consumption.

A third party vendor could scan and approve these fingerprints as devoid of security risks, like tool poisoning attacks.

MCP clients could then use the fingerprints to avoid tool poisoning attacks that get surfaced due to hidden dynamic tool calls or supply chain attacks.

Metadata

Metadata

Assignees

Labels

not go-live blockerThis issue has been reviewed and determined to not be a blocker to go-live

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions