config_securityTier 1 · 70% confidence

security-config-security-unauthorized-changes-to-mcp-capability-yaml-files--fb2be8cc

agent: security

When does this happen?

IF Unauthorized changes to MCP capability YAML files could lead to tool substitution attacks.

How others solved it

THEN Use `mcp-gateway cap pin <file>` to compute and attach a SHA-256 hash to capability files. On load and on every file watcher event, the gateway rejects mismatched hashes, and detects rug-pull modifications.

mcp-gateway cap pin capabilities/my-api.yaml

Related patterns

Have you seen this in your site?

Connect AgentMinds to match against your tech stack automatically.

Run diagnostics