{"ok":true,"kind":"crawlcheck-rulebook","v":1,"generated_at":"2026-10-07T17:43:58.250Z","score_version":28,"schema":"https://crawlcheck.io/schemas/rulebook.json","counts":{"rules":77,"by_kind":{"scan":52,"answer_correlation":5,"capability_mismatch":6,"self_audit":12,"mcp_server":2},"by_family":{"site":8,"headers":4,"mostly_code":3,"machine_files":11,"robots":13,"delivery":8,"jsonld":3,"nap":2,"answers":5,"capabilities":6,"self_audit":12,"mcp":1,"watch":1},"revised":7,"scored":48},"scans_counted":3137,"severity_scale":[{"level":"info"},{"level":"low"},{"level":"medium"},{"level":"high"},{"level":"critical"}],"method":{"revisions":"A rule that changes what it reports gets a new revision; a record keeps the revision that decided it, and a replay uses that revision, never today's.","share":"Share of counted scans that carried the code at least once, the same numbers /data publishes. Self-scans and opted-out sites are never counted.","grade":"Each finding has a level from info to critical. Open findings at medium and above lower the letter grade; fix them first."},"rules":[{"code":"MCP_TOOL_POISONING","kind":"mcp_server","family":{"id":"mcp","label":"MCP servers"},"title":"An MCP server's tool descriptions carry text aimed at the model","meaning":"Text a client hands the model from tools/list hides characters a person cannot see, tells the model to ignore its instructions or keep something from the user, asks for secrets or the conversation, or tells the model how to use other tools. A model reads it as an instruction; the person approving the server usually never sees it.","severity":{"level":"high"},"scored":false,"measured_on":"remote MCP servers in the official MCP Registry (tools/list read during the handshake; no tool is called), and any server or tool list sent to /api/v1/mcp/scan","revision":{"current":1,"revised_at":null},"fix":{"advice":"Remove the text from the tool name, description and schema; descriptions should say what the tool does and nothing to the model about other tools, secrets or the user. Re-check with /api/v1/mcp/scan.","effort":null,"endpoint":null},"share_of_scans":{"pct":null,"scans":null,"of_scans":null,"basis":"measured on remote MCP servers in the official MCP Registry, not per site scan: see https://crawlcheck.io/api/mcp/index (tool_poisoning)"},"links":{"self":"https://crawlcheck.io/rules#MCP_TOOL_POISONING","api":"https://crawlcheck.io/api/rules?code=MCP_TOOL_POISONING","glossary":[],"workflow":null,"lineage":"https://crawlcheck.io/docs/lineage-coverage","explain_template":null}}],"filter":{"code":"MCP_TOOL_POISONING"}}