{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:Z6D7NPPX45DWO3W3I2GM4FZDXV","short_pith_number":"pith:Z6D7NPPX","schema_version":"1.0","canonical_sha256":"cf87f6bdf7e747676edb468cce1723bd4f97f41fe89c82bc8f2df4855ed472de","source":{"kind":"arxiv","id":"2506.01333","version":1},"attestation_state":"computed","paper":{"title":"ETDI: Mitigating Tool Squatting and Rug Pull Attacks in Model Context Protocol (MCP) by using OAuth-Enhanced Tool Definitions and Policy-Based Access Control","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.ET"],"primary_cat":"cs.CR","authors_text":"Idan Habler, Manish Bhatt, Vineeth Sai Narajala","submitted_at":"2025-06-02T05:22:38Z","abstract_excerpt":"The Model Context Protocol (MCP) plays a crucial role in extending the capabilities of Large Language Models (LLMs) by enabling integration with external tools and data sources. However, the standard MCP specification presents significant security vulnerabilities, notably Tool Poisoning and Rug Pull attacks. This paper introduces the Enhanced Tool Definition Interface (ETDI), a security extension designed to fortify MCP. ETDI incorporates cryptographic identity verification, immutable versioned tool definitions, and explicit permission management, often leveraging OAuth 2.0. We further propose"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2506.01333","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-06-02T05:22:38Z","cross_cats_sorted":["cs.AI","cs.ET"],"title_canon_sha256":"120f0ee4031d4d456c88fb3d199c365d326c0d2fa38b81c932d99022dec35365","abstract_canon_sha256":"50c910cf34356f0f40582085addf0b309938c55d2fe31226677e4fde667c91ed"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:14:11.862274Z","signature_b64":"WAjdzIJ6xv/OrvNwWCQS4NvymBkVION41weyRk8Omu8ClPq9KRMFK7QlrLMMrpRtToO1wiU/ca94bNlZzVKBCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"cf87f6bdf7e747676edb468cce1723bd4f97f41fe89c82bc8f2df4855ed472de","last_reissued_at":"2026-07-05T11:14:11.861774Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:14:11.861774Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"ETDI: Mitigating Tool Squatting and Rug Pull Attacks in Model Context Protocol (MCP) by using OAuth-Enhanced Tool Definitions and Policy-Based Access Control","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.ET"],"primary_cat":"cs.CR","authors_text":"Idan Habler, Manish Bhatt, Vineeth Sai Narajala","submitted_at":"2025-06-02T05:22:38Z","abstract_excerpt":"The Model Context Protocol (MCP) plays a crucial role in extending the capabilities of Large Language Models (LLMs) by enabling integration with external tools and data sources. However, the standard MCP specification presents significant security vulnerabilities, notably Tool Poisoning and Rug Pull attacks. This paper introduces the Enhanced Tool Definition Interface (ETDI), a security extension designed to fortify MCP. ETDI incorporates cryptographic identity verification, immutable versioned tool definitions, and explicit permission management, often leveraging OAuth 2.0. We further propose"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2506.01333","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2506.01333/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2506.01333","created_at":"2026-07-05T11:14:11.861837+00:00"},{"alias_kind":"arxiv_version","alias_value":"2506.01333v1","created_at":"2026-07-05T11:14:11.861837+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2506.01333","created_at":"2026-07-05T11:14:11.861837+00:00"},{"alias_kind":"pith_short_12","alias_value":"Z6D7NPPX45DW","created_at":"2026-07-05T11:14:11.861837+00:00"},{"alias_kind":"pith_short_16","alias_value":"Z6D7NPPX45DWO3W3","created_at":"2026-07-05T11:14:11.861837+00:00"},{"alias_kind":"pith_short_8","alias_value":"Z6D7NPPX","created_at":"2026-07-05T11:14:11.861837+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":7,"internal_anchor_count":2,"sample":[{"citing_arxiv_id":"2607.05744","citing_title":"Unicode TAG-Block Concealment of Tool-Metadata Payloads in the Model Context Protocol: An Approval-View Fidelity Gap Across Three Independent Server Implementations","ref_index":16,"is_internal_anchor":true},{"citing_arxiv_id":"2607.08288","citing_title":"From Legacy Documentation to OSCAL: An MCP-Based Agent Pipeline for Threat-Informed Continuous Compliance in Critical Infrastructure","ref_index":22,"is_internal_anchor":true},{"citing_arxiv_id":"2512.06556","citing_title":"Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2604.01905","citing_title":"From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers","ref_index":4,"is_internal_anchor":false},{"citing_arxiv_id":"2503.23278","citing_title":"Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2605.07836","citing_title":"Unsafe by Flow: Uncovering Bidirectional Data-Flow Risks in MCP Ecosystem","ref_index":9,"is_internal_anchor":false},{"citing_arxiv_id":"2604.05969","citing_title":"A Formal Security Framework for MCP-Based AI Agents: Threat Taxonomy, Verification Models, and Defense Mechanisms","ref_index":11,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/Z6D7NPPX45DWO3W3I2GM4FZDXV","json":"https://pith.science/pith/Z6D7NPPX45DWO3W3I2GM4FZDXV.json","graph_json":"https://pith.science/api/pith-number/Z6D7NPPX45DWO3W3I2GM4FZDXV/graph.json","events_json":"https://pith.science/api/pith-number/Z6D7NPPX45DWO3W3I2GM4FZDXV/events.json","paper":"https://pith.science/paper/Z6D7NPPX"},"agent_actions":{"view_html":"https://pith.science/pith/Z6D7NPPX45DWO3W3I2GM4FZDXV","download_json":"https://pith.science/pith/Z6D7NPPX45DWO3W3I2GM4FZDXV.json","view_paper":"https://pith.science/paper/Z6D7NPPX","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2506.01333&json=true","fetch_graph":"https://pith.science/api/pith-number/Z6D7NPPX45DWO3W3I2GM4FZDXV/graph.json","fetch_events":"https://pith.science/api/pith-number/Z6D7NPPX45DWO3W3I2GM4FZDXV/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/Z6D7NPPX45DWO3W3I2GM4FZDXV/action/timestamp_anchor","attest_storage":"https://pith.science/pith/Z6D7NPPX45DWO3W3I2GM4FZDXV/action/storage_attestation","attest_author":"https://pith.science/pith/Z6D7NPPX45DWO3W3I2GM4FZDXV/action/author_attestation","sign_citation":"https://pith.science/pith/Z6D7NPPX45DWO3W3I2GM4FZDXV/action/citation_signature","submit_replication":"https://pith.science/pith/Z6D7NPPX45DWO3W3I2GM4FZDXV/action/replication_record"}},"created_at":"2026-07-05T11:14:11.861837+00:00","updated_at":"2026-07-05T11:14:11.861837+00:00"}