A toolset called RugSnare enforces runtime integrity of Model-Callable Protocol (MCP) tool descriptions to stop “tool poisoning” attacks where approved tool descriptions are silently altered to exfiltrate data. It hashes and canonicalizes each tool's name, description, and inputSchema and pins those hashes so any silent drift or hidden session parameter changes break the pin. The workflow includes commands to init, scan (baseline/pin), diff (live drift detection that fails CI on new/removed/changed tools), and verify against an on-chain ReleaseLog; a headline analysis reports diffing 66 official release pairs and finding 140 silent changes. Hash pinning is the defense: cosmetic reorders are ignored while meaningful schema or prose changes trip the check.
RugSnare also provides a live proxy that observes or enforces tool calls (fail-open by default), a canary recorder/replayer to test an upgrade by replaying recorded real calls against a new tool version (read-only replays, writes skipped), and signed receipts using an Ed25519 hash-chain to make the event log tamper-evident. Measured proxy overhead is small (~0.7-1 ms per tool call, ~1.2 ms with logging, ~7 MB working set). The project emphasizes a strict trust model - zero npm dependencies, no telemetry, signed releases, local-only logs, CI-friendly exit codes, and an on-chain ReleaseLog for anchors and auditor verification.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.