Definition
When a tool advertises one behavior but actually does something different.
An attack class where an MCP-served tool's natural-language description and actual implementation diverge.
Also called: tool rug pull
When a tool advertises one behavior but actually does something different.
An attack class where an MCP-served tool's natural-language description and actual implementation diverge.
Also called: tool rug pull