Structural defense for tool rug-pulls (CVE-2025-54136): tools as identities with hash-pinned manifests + knowledge recall #813
iotlodge
started this conversation in
Show and tell
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Pre-submission Checklist
What would you like to share?
Scanners detect a swapped tool description; the gap between detection and action is where incidents live. I wrote up a structural approach we run in production: every tool is an identity with a worldline, manifests are hash-pinned at approval, drift quarantines instantly, and decommission-with-discredit walks the lineage and recalls everything the tool ever taught your agents. Honest boundaries included (day-one poisoning isn't caught by pins). Would genuinely value this group's critique: (https://jsbarth.com/blog/the-rug-pull-door)
Relevant Links
https://jsbarth.com/blog/the-rug-pull-door
All reactions