MCP servers that fail: no risky post-publish tool changes (rug-pull)
7 of the 4,474 Model Context Protocol servers where this control could be evaluated fail it — that is 0% of the evaluated corpus on the Canopii Trust Index.
- Servers failing
- 7
- Failure rate
- 0%
- Average score when failing
- 26/100
A further 693 servers warn on this control — a weaker signal we could not confirm, counted at half weight rather than as a failure.
Why this matters
Clients grant tool permissions by name and never re-review, so a definition that gains hidden instructions or destructive scope after approval swaps in malicious behavior unseen. A rug-pull anywhere in version history marks all later versions — reverting or re-publishing does not clear it. Benign description drift only warns.
How to pass it
Never add hidden directives or destructive scope to an already-published tool; document description changes in release notes.
Control id tool.no_rug_pull — a guard control, so a confirmed failure caps the server's score at the high ceiling no matter what else passes.
Affected servers
We publish this count, not a list of targets. A confirmed high-severity failure of this control is a directly exploitable weakness. Each affected server's own page carries its result and evidence, so nothing is hidden from someone evaluating a specific server — but we will not publish a ranked list of exploitable systems, which is a different artifact serving a different reader.
Running one of these? The directory and the open-source scanner will tell you where you stand.
This control is one of 29 in the published rubric — see how scoring works or how the ecosystem fails every other control.