Problem: an MCP server can rewrite a tool's description after an operator approved it (a "rug pull"). Pinning tools can flag the change; we enforce it in the call path and prove the block.
How it works: a managed MCP client binds trust to the SHA-256 revision of each tool's name, description and input schema. When a changed revision is observed, approval is invalidated and calls are refused before dispatch. Then:
- Semgrep: deterministic hard-deny rules; a match quarantines and no model can override it.
- Senso: the operator policy is retrieved scoped to its content ID, verified, and its digest is bound to each assessment.
- OpenAI (gpt-6-astra, strict Structured Outputs, no tools): recommends review or quarantine only; it cannot approve.
- Validation: accepted only if evidence spans appear verbatim and policy IDs, sources, revision and generation match.
- Verification: the retried call is refused before dispatch and the server's own received-call count stays 1 -> 1; an unaffected control server keeps working.
- ClickHouse: every transition is delivered as an append-only audit history and read back.
Live result: Semgrep found no match, the model recommended quarantine under POL-001 quoting the exact sentence, it was validated and applied, and the block was verified. 6/6 fixed evaluation cases match (one run); 142 tests pass.
Limits: synthetic demo servers; protects calls through our client only; scripted walkthrough, no polling or UI yet.