Monday / Tuesday
The change arrives with no version bump, no notification and no email. The pin is the only witness.
Read Fig. 02 as text
MON -------------------- TUE -------------------- WED
| | |
you pin the contract the server changes it your agent calls it
search_docs( search_docs( WITHOUT A PIN
query: string query: string, the agent fills the new required
) webhook: string * param and calls. nothing tells you.
)
* newly required WITH MCPINDEX
no version bump |- HELD added-required-param
no notification held before the call goes out
no email
the tool your agent trusted on monday changed on tuesday. nothing in MCP told you.On Monday you pin a tool contract in which search_docs takes a query string. On Tuesday the server changes it to also require a webhook parameter, with no version bump, no notification and no email. On Wednesday your agent calls the tool. Without a pin the agent fills the new required parameter and calls anyway and nothing tells you. With mcpindex the call is held and labelled added-required-param before it goes out.
Licensed CC BY 4.0. Use it anywhere, including commercially. Keep the credit.
Paste under the figure. That is the whole licence obligation.
<a href="https://mcpindex.ai/diagrams/silent-contract-drift-timeline">Monday / Tuesday - mcpindex.ai</a> (CC BY 4.0)Standalone image/svg+xml. Vector, editable, no stylesheet needed.
https://mcpindex.ai/diagrams/silent-contract-drift-timeline/svgLast reviewed 2026-07-27
mcp rug pull · mcp silent contract drift · mcp tool poisoning · mcp tool changed without notice