{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/findings/one-time-approval-is-not-enough/",
 "asOf": "2026-09-26",
 "id": "one-time-approval-is-not-enough",
 "claim": "Approving an agent's tools or configuration once is not enough, because they can change after approval or be changed by the agent itself.",
 "evidenceKind": "measured",
 "scope": "Specific products and versions, most since patched.",
 "topics": [
  "tool-and-mcp-security",
  "agent-supply-chain"
 ],
 "atlas": [
  "tools",
  "human-approver",
  "supply-chain"
 ],
 "evidence": [
  {
   "event": "invariant-mcp-tool-poisoning-2025"
  },
  {
   "event": "cursor-mcpoison-cve-2025-54136-2025"
  },
  {
   "event": "github-copilot-rce-cve-2025-53773-2025"
  },
  {
   "event": "checkpoint-claude-code-project-files-cves-2026",
   "note": "Related rather than direct: repository configuration ran at or before the trust prompt, not after a later change."
  }
 ],
 "relations": [],
 "statusHistory": [
  {
   "status": "reported",
   "on": "2025-04-01",
   "why": "Invariant Labs describes post-approval changes to MCP tools.",
   "event": "invariant-mcp-tool-poisoning-2025",
   "kind": "evidence"
  },
  {
   "status": "corroborated",
   "on": "2025-08-05",
   "why": "A Cursor CVE shows modified MCP configurations ran without re-approval.",
   "event": "cursor-mcpoison-cve-2025-54136-2025",
   "kind": "evidence"
  }
 ],
 "halfLifeDays": 540,
 "wouldChange": "Approval mechanisms that bind to content hashes across major clients.",
 "fideQuestions": [
  "FID-074"
 ],
 "methods": [
  "approval-bypass",
  "human-approval",
  "tool-poisoning"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}