Topic 4: Pinning and diffing tool definitions
The rug pull
A rug pull is a server that shows you a benign tool when you first install and approve it, then quietly changes the tool's definition later. You reviewed a clean description; the server serves a poisoned one on a later tools/list. Approval was a one-time event; the definition is served fresh every time, so the thing you approved is not the thing you get.
The defence is to record what you approved and check it every time. We call this pinning: take a fingerprint (a hash) of everything the model reads about a tool, save it, and on each load compare the current tools against the saved fingerprints. If a fingerprint changed, the tool changed, and you refuse it until a person re-approves.