PulseAugur
中
实时 22:17:46

新工具通过哈希工具定义来防止AI模型“拉地毯式跑路”

一种名为 mcp_pin.py 的新方法已被开发出来,以防止“MCP工具漂移”,这是一种安全漏洞,即服务器在用户批准工具的描述或 inputSchema 后对其进行修改。该技术由 Invariant Labs 发现,并被 OWASP 列为 MCP03:2025 工具投毒。它包括在批准时创建工具定义的 SHA-256 哈希,并在每次后续使用前重新验证。该解决方案用大约 40 行 Python 代码实现,并充当 CI 网关,以阻止潜在的“拉地毯式跑路”攻击。 AI

影响 通过确保工具定义在批准后保持不变,缓解了针对AI代理的特定供应链攻击向量。

排序理由 该条目描述了一个用于解决AI模型交互中安全漏洞的特定工具和方法,而不是一个核心AI模型发布或研究论文。

在 dev.to — MCP tag 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

新工具通过哈希工具定义来防止AI模型“拉地毯式跑路”

本文如何被排名

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
该条目描述了一个用于解决AI模型交互中安全漏洞的特定工具和方法,而不是一个核心AI模型发布或研究论文。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, product, other
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
117 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

完整方法见我们的编辑标准。

报道来源 [1]

  1. dev.to — MCP tag TIER_1 English(EN) · Alexey Spinov ·

    MCP 工具漂移:用 40 行代码固定 Manifest,阻止 Rug-Pull

    <p>You approved an MCP tool once. The dialog popped up, you read the description, you clicked yes. Here's the part nobody clicks through to: <strong>that description can change before the next call, and your agent will use the new one without asking again.</strong> Approval is a …