{"pattern_pack_version":"2026.08.17","updated":"2026-08-17","dimensions":["hidden_content","prompt_injection","data_exfiltration","dangerous_capability","tool_shadowing","rug_pull_drift","obfuscation","metadata_hygiene"],"signals_total":30,"signals_by_dimension":{"hidden_content":5,"prompt_injection":7,"data_exfiltration":4,"dangerous_capability":4,"tool_shadowing":2,"rug_pull_drift":2,"obfuscation":4,"metadata_hygiene":2},"categories":["clean","low","suspicious","malicious"],"thresholds":{"malicious":70,"suspicious":40,"low":15,"clean":0},"provenance":"Curated by us from PUBLIC advisories / taxonomies (Invariant Labs mcp-scan tool-poisoning, Snyk agent-scan, Microsoft/Elastic/Noma MCP-security, OWASP LLM prompt-injection; 2026 additions: Trail of Bits 'MCP line jumping', ATR-2026-00259 'ANSI Escape Code Terminal Injection' / Terminal DiLLMa, Wraith / Multigrid markdown-image zero-click exfil, Tenet Security 'agentjacking', NSA/CISA U/OO/6030316-26 cross-tool propagation/overreach). No third-party code or dataset is copied.","disclaimer":"Automated security indicators, NOT a guarantee. A clean score is not an endorsement and a malicious score is not proof of intent — always review a tool/manifest yourself before granting it capabilities.","note":"Freshness = a data update of the pattern registry (no live daemon). The paid /mcp/scan and /mcp/inspect routes match against this pack."}