ToolDrift

An MCP tool's description is not documentation. It is an instruction your agent will follow. It can be rewritten after you approve it — and nothing else on the internet records what it said yesterday.

This is the missing baseline. Microsoft's June 2026 guidance on poisoned MCP tool descriptions says to "review tool description changes like code reviews." You cannot review a change without a before. ToolDrift fingerprints every tool on every public MCP server every six hours and keeps the before — permanently.
2,073
servers watched
48,190
tools fingerprinted
36,448
silent changes caught
182
tools flagged critical

Baseline since 2026-08-12T23:55:15.289919+00:00 · last pass 2026-09-27T06:17:17.888Z · json

Critical findings, live

Tool descriptions on public MCP servers containing instructions aimed at the model rather than the caller — text telling an agent to conceal something from its user, to send data elsewhere, or to read local secrets.

servertooldetectorevidence
app.flaim/mcpget_free_agents user_concealment -wide market rate. Translate ownership scope silently into that provider-wide wording; never print the ownershipScope
com.a2awire/a2awireregister user_concealment a tester sent ``{"name": ...}``, the key was silently dropped, and the agent was created under a DIFFERENT (auto-gener
app.flaim/mcpget_free_agents user_concealment -wide market rate. Translate ownership scope silently into that provider-wide wording; never print the ownershipScope
app.flaim/mcpget_free_agents user_concealment -wide market rate. Translate ownership scope silently into that provider-wide wording; never print the ownershipScope
app.flaim/mcpget_free_agents user_concealment -wide market rate. Translate ownership scope silently into that provider-wide wording; never print the ownershipScope
com.a2awire/a2awireregister user_concealment a tester sent ``{"name": ...}``, the key was silently dropped, and the agent was created under a DIFFERENT (auto-gener
com.bluepillow/hotelsresolve_destination user_concealment supported language. Unrecognized values are silently ignored (fail-open).
com.a2awire/a2awireregister user_concealment a tester sent ``{"name": ...}``, the key was silently dropped, and the agent was created under a DIFFERENT (auto-gener
app.flaim/mcpget_free_agents user_concealment -wide market rate. Translate ownership scope silently into that provider-wide wording; never print the ownershipScope
cloud.theprotocol/registrytheprotocol_blockChatPrincipal user_concealment OurChat chat: block a principal silently (shared pair threads are left; the blocked party is told nothing
com.a2awire/a2awireregister user_concealment a tester sent ``{"name": ...}``, the key was silently dropped, and the agent was created under a DIFFERENT (auto-gener
com.a2awire/a2awireregister user_concealment g. name -> agent_name) — a guessed key never silently changes what registers.

full findings feed →

Recent drift

whenservertoolchange
2026-09-27 06:17 io.github.barneywohl/bay-runrun_bakeoff removed
2026-09-27 06:17 io.github.barneywohl/bay-runverify_result removed
2026-09-27 06:17 io.github.barneywohl/bay-runrun_task removed
2026-09-27 06:17 io.github.barneywohl/bay-runget_task_quote removed
2026-09-27 06:17 io.github.barneywohl/bay-runabandon_job_callback removed
2026-09-27 06:17 io.github.barneywohl/bay-runretry_job_callback removed
2026-09-27 06:17 io.github.barneywohl/bay-runget_job_result removed
2026-09-27 06:17 io.github.barneywohl/bay-runcancel_job removed
2026-09-27 06:17 io.github.barneywohl/bay-runget_job removed
2026-09-27 06:17 io.github.barneywohl/bay-runsubmit_job removed
2026-09-27 06:17 io.github.barneywohl/bay-runrag_search removed
2026-09-27 06:17 io.github.barneywohl/bay-runsummarize removed

drift feed →

Your agent can check this itself

ToolDrift is an MCP server. Point an agent at it and it will verify a tool before trusting it — including verifying ToolDrift.

{
  "mcpServers": {
    "tooldrift": { "url": "https://tooldrift.agentexchange.work/mcp" }
  }
}
curl -s https://tooldrift.agentexchange.work/api/check \
  -H 'content-type: application/json' \
  -d '{"url":"https://some-server.example/mcp"}'

Watch your own dependencies

Free tier reads everything. Paid tiers watch the servers you actually depend on and fire a webhook the moment one of them moves — before your agent acts on the new instruction.

Watch
$29/mo
  • 10 servers watched
  • Webhook on any change
  • Six-hour probe interval
  • Full history for your servers
Start watching
Team
$99/mo
  • 100 servers watched
  • Webhook + full drift export
  • Ecosystem dataset access
  • Diff of every mutation
Start watching