Skip to main content
Run any Skill in Manus
with one click

remediate-mcp-tool-quarantine

Stars3
Forks0
UpdatedJuly 9, 2026 at 18:17

Quarantine an MCP tool flagged by detect-mcp-tool-drift (T1195.001 supply chain compromise) or detect-prompt-injection-mcp-proxy (MITRE ATLAS AML.T0051) by appending a structured entry to a JSONL quarantine file the operator's MCP client reads at startup or via hot-reload to exclude the tool from its discoverable surface. Every action is dry-run by default, deny-listed against MCP infrastructure prefixes (mcp_, system_, internal_), gated behind an incident ID plus two distinct approvers for --apply, and dual-audited (DynamoDB + KMS-encrypted S3). Re-verify reads the quarantine file and emits VERIFIED, DRIFT, or UNREACHABLE via the shared remediation_verifier contract — DRIFT also emits a paired OCSF Detection Finding so the gap flows back through the SIEM/SOAR pipeline. Use when the user mentions "quarantine an MCP tool," "block a poisoned MCP tool," "respond to MCP tool drift," "remediate prompt injection in MCP proxy," or "re-verify MCP tool quarantine." Do NOT use for cloud IAM revocation, Kubernetes conta

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
8 files
SKILL.md
readonly